Vulnerability index

Browse CVEs

146 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open5gs MEDIUM 5.5
CVE-2025-15417

A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request of the file src/sgwc/s11-handl…

Fix: after 2.7.6
Fix from $1,600 2026-01-01
Open5gs HIGH 7.5
CVE-2025-15176

A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule…

Fix: after 2.7.5
Fix from $1,950 2025-12-29
Open5gs MEDIUM 5.9
CVE-2025-14954

A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_o…

Fix: after 2.7.5
Fix from $1,600 2025-12-19
Open5gs MEDIUM 5.3
CVE-2025-14953

A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component…

Fix: after 2.7.5
Fix from $1,600 2025-12-19
Open5gs HIGH 7.5
CVE-2025-65559

An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachabl…

No fix yet
Fix from $1,950 2025-12-18
Open5gs HIGH 7.5
CVE-2025-63288

In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.

Patch available
Fix from $1,950 2025-11-10
Open5gs HIGH 7.5
CVE-2025-41068

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is …

Fix: 2.7.5+
Fix from $1,950 2025-10-27
Open5gs HIGH 7.5
CVE-2025-41067

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI r…

Fix: 2.7.5+
Fix from $1,950 2025-10-27
Open5gs HIGH 7.5
CVE-2025-52322

An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (…

Fix: after 2.7.2
Fix from $1,950 2025-09-09
Open5gs HIGH 7.5
CVE-2025-52288

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) compo…

Fix: after 2.7.5
Fix from $1,950 2025-09-08
Open5gs MEDIUM 5.3
CVE-2025-9405

A security flaw has been discovered in Open5GS up to 2.7.5. The impacted element is the function gmm_state_exception of the file src/amf/gmm-sm.c. Th…

Fix: 2.7.6+
Fix from $1,600 2025-08-25
Open5gs HIGH 7.5
CVE-2025-8805

A vulnerability was determined in Open5GS up to 2.7.5. Affected by this issue is the function smf_gsm_state_wait_pfcp_deletion of the file src/smf/gs…

Fix: 2.7.6+
Fix from $1,950 2025-08-10
Open5gs HIGH 7.5
CVE-2025-8804

A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ngap_build_downlink_nas_transport of the component A…

Fix: 2.7.6+
Fix from $1,950 2025-08-10
Open5gs HIGH 7.5
CVE-2025-8803

A vulnerability has been found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-s…

Fix: 2.7.6+
Fix from $1,950 2025-08-10
Open5gs HIGH 7.5
CVE-2025-8802

A vulnerability was determined in Open5GS up to 2.7.5. This vulnerability affects the function smf_state_operational of the file src/smf/smf-sm.c of …

Fix: 2.7.6+
Fix from $1,950 2025-08-10
Open5gs HIGH 7.5
CVE-2025-8801

A vulnerability was found in Open5GS up to 2.7.5. This affects the function gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. Th…

Fix: 2.7.6+
Fix from $1,950 2025-08-10
Open5gs HIGH 7.5
CVE-2025-8800

A vulnerability has been found in Open5GS up to 2.7.5. Affected by this issue is the function esm_handle_pdn_connectivity_request of the file src/mme…

Fix: 2.7.6+
Fix from $1,950 2025-08-10
Open5gs HIGH 7.5
CVE-2025-8799

A vulnerability was identified in Open5GS up to 2.7.5. Affected by this vulnerability is the function amf_npcf_am_policy_control_build_create/amf_nsm…

Fix: 2.7.6+
Fix from $1,950 2025-08-10
Open5gs HIGH 7.1
CVE-2025-29646

An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest pac…

Fix: after 2.7.2
Fix from $1,950 2025-06-18
Open5gs HIGH 7.8
CVE-2025-44952

A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local att…

Fix: after 2.7.2
Fix from $1,950 2025-06-18
Open5gs HIGH 7.1
CVE-2025-44951

A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a local attack…

Fix: after 2.7.2
Fix from $1,950 2025-06-18
Open5gs HIGH 7.5
CVE-2025-5935

A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register…

Fix: 2.7.6+
Fix from $1,950 2025-06-10
Open5gs MEDIUM 5.3
CVE-2025-5520

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_…

Fix: after 2.7.3
Fix from $1,600 2025-06-03
Open5gs MEDIUM 5.3
CVE-2025-5501

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_re…

Fix: after 2.7.3
Fix from $1,600 2025-06-03
Open5gs HIGH 7.5
CVE-2025-29339

An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing…

Fix: after 2.7.2
Fix from $1,950 2025-04-22
Open5gs MEDIUM 6.5
CVE-2025-25774

An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an excep…

Patch available
Fix from $1,600 2025-03-12
Open5gs HIGH 7.5
CVE-2025-1925

A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle…

Fix: after 2.7.2
Fix from $1,950 2025-03-04
Open5gs HIGH 7.5
CVE-2025-1893

A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authe…

Fix: after 2.7.2
Fix from $1,950 2025-03-04
Open5gs HIGH 7.5
CVE-2024-56921

An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handli…

Patch available
Fix from $1,950 2025-02-03
Open5gs HIGH 7.5
CVE-2024-57519

An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.

Patch available
Fix from $1,950 2025-01-28