4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): Low (L)
- Exploit Code Maturity (E): Proof-of-Concept (P)
- Remediation Level (RL): Not Defined (X)
- Report Confidence (RC): Reasonable (R)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): Low (L)
Activity log
- Created suggestion
Open5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of service
A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /src/bsf/context.c of the component BSF. This manipulation of the argument ipv6Prefix causes denial of service. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
-
VDB-360530 | Open5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of service vdb-entrytechnical-description
-
-
Submit #804322 | Open5gs BSF v2.7.7 Denial of Service third-party-advisory
-
Affected products
- ==2.7.6
- ==2.7.0
- ==2.7.3
- ==2.7.5
- ==2.7.4
- ==2.7.7
- ==2.7.2
- ==2.7.1
Matching in nixpkgs
pkgs.open5gs
4G/5G core network components
Package maintainers
-
@xddxdd Yuhui Xu <b980120@hotmail.com>
-
@Bot-wxt1221 Bot-wxt1221 <3264117476@qq.com>