Vulnerability index

Browse CVEs

146 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open5gs CRITICAL 9.8
CVE-2024-40129

Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

Patch available
Fix from $2,300 2024-07-16
Open5gs CRITICAL 9.8
CVE-2024-40130

open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

Patch available
Fix from $2,300 2024-07-16
Open5gs MEDIUM 5.3
CVE-2024-33382

An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration

No fix yet
Fix from $1,600 2024-05-08
Open5gs HIGH 7.5
CVE-2024-34475

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/g…

Fix: 2.7.1+
Fix from $1,950 2024-05-05
Open5gs MEDIUM 5.3
CVE-2024-34476

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common…

Fix: 2.7.1+
Fix from $1,600 2024-05-05
Open5gs HIGH 7.5
CVE-2023-50020

An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

Patch available
Fix from $1,950 2024-01-02
Open5gs MEDIUM 5.9
CVE-2023-50019

An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handli…

Patch available
Fix from $1,600 2024-01-02
Open5gs HIGH 7.5
CVE-2023-4882

DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() fu…

Fix: after 2.4.10
Fix from $1,950 2023-10-03
Open5gs HIGH 7.5
CVE-2023-4883

Invalid pointer release vulnerability. Exploitation of this vulnerability could allow an attacker to interrupt the correct operation of the service b…

Fix: after 2.4.10
Fix from $1,950 2023-10-03
Open5gs HIGH 7.5
CVE-2023-4884

An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

Fix: after 2.4.10
Fix from $1,950 2023-10-03
Open5gs MEDIUM 5.9
CVE-2023-4885

Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure o…

Fix: after 2.4.10
Fix from $1,600 2023-10-03
Open5gs HIGH 7.5
CVE-2023-23846

Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS …

Fix: 2.4.13+
Fix from $1,950 2023-02-01
Open5gs HIGH 7.5
CVE-2022-43221

open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial o…

No fix yet
Fix from $1,950 2022-11-01
Open5gs HIGH 7.5
CVE-2022-43222

open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial o…

No fix yet
Fix from $1,950 2022-11-01
Open5gs HIGH 7.5
CVE-2022-43223

open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Ser…

No fix yet
Fix from $1,950 2022-11-01
Open5gs HIGH 7.5
CVE-2022-40890

A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.

Fix: after 2.4.10
Fix from $1,950 2022-09-29
Open5gs HIGH 7.5
CVE-2022-3354

A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown code in the library lib/core…

Fix: after 2.4.10
Fix from $1,950 2022-09-28
Open5gs MEDIUM 6.5
CVE-2022-3299

A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in…

Fix: after 2.4.10
Fix from $1,600 2022-09-26
Open5gs HIGH 7.5
CVE-2022-39063

When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Response. Once U…

Fix: after 2.4.9
Fix from $1,950 2022-09-16
Open5gs HIGH 7.5
CVE-2021-44108

A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi requ…

Fix: after 2.3.6
Fix from $1,950 2022-04-05
Open5gs HIGH 7.5
CVE-2021-44109

A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.

Fix: after 2.3.6
Fix from $1,950 2022-04-05
Open5gs HIGH 7.5
CVE-2021-44081

A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of …

Patch available
Fix from $1,950 2022-03-29
Open5gs HIGH 7.5
CVE-2021-45462

In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.

Patch available
Fix from $1,950 2021-12-23
Open5gs HIGH 7.5
CVE-2021-41794

ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can s…

Fix: after 2.3.3
Fix from $1,950 2021-10-07
Open5gs CRITICAL 9.8
CVE-2021-28122

A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a cr…

Fix: after 2.2.0
Fix from $2,300 2021-03-10
Open5gs HIGH 8.8
CVE-2021-25863

Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

No fix yet
Fix from $1,950 2021-01-26