CVE-2025-29646

HIGH

open5gs < 2.7.2 - Denial of Service via Crafted PFCP SessionEstablishmentRequest Packet

Title source: llm
STIX 2.1

Description

An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).

References (2)

Core 2
Core References

Scores

CVSS v3 7.1
EPSS 0.0023
EPSS Percentile 46.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
open5gs/open5gs < 2.7.2
Published Jun 18, 2025
Tracked Since Feb 18, 2026