Metrics
Affected Vendors & Products
Thu, 06 Mar 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Open5gs
Open5gs open5gs |
|
CPEs | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
Vendors & Products |
Open5gs
Open5gs open5gs |
Tue, 04 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 04 Mar 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component UDM Subscriber Data Management. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named e31e9965f00d9c744a7f728497cb4f3e97744ee8. It is recommended to apply a patch to fix this issue. | A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vulnerability allows a single UE to crash the AMF, resulting in the complete loss of mobility and session management services and causing a network-wide outage. All registered UEs will lose connectivity, and new registrations will be blocked until the AMF is restarted, leading to a high availability impact. The exploit has been disclosed to the public and may be used. The patch is named e31e9965f00d9c744a7f728497cb4f3e97744ee8. It is recommended to apply a patch to fix this issue. |
Title | Open5GS UDM Subscriber Data Management gmm-sm.c gmm_state_authentication denial of service | Open5GS AMF gmm-sm.c gmm_state_authentication denial of service |
Tue, 04 Mar 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component UDM Subscriber Data Management. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named e31e9965f00d9c744a7f728497cb4f3e97744ee8. It is recommended to apply a patch to fix this issue. | |
Title | Open5GS UDM Subscriber Data Management gmm-sm.c gmm_state_authentication denial of service | |
Weaknesses | CWE-404 | |
References |
|
|
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-04T00:00:13.888Z
Updated: 2025-03-04T16:35:55.193Z
Reserved: 2025-03-03T18:13:26.198Z
Link: CVE-2025-1893

Updated: 2025-03-04T16:35:39.679Z

Status : Analyzed
Published: 2025-03-04T01:15:11.327
Modified: 2025-03-06T12:21:35.360
Link: CVE-2025-1893

No data.