Multiple vulnerabilities in Open5GS
CVE-2023-4882

7.5HIGH

Key Information:

Vendor

Open5gs

Status
Vendor
CVE Published:
3 October 2023

What is CVE-2023-4882?

This vulnerability in Open5GS allows an attacker to introduce a new Virtual Network Function (VNF) value, which may lead to a Denial of Service condition. The malicious registration triggers the args_assets() function located in the arg-log.php file, subsequently executing the args-abort.c script. This sequence results in the abrupt termination of the service, impacting availability and potentially leading to further exploitation.

Affected Version(s)

Open5GS 2.4.10 and prior

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo Valle Alvear
.
CVE-2023-4882 : Multiple vulnerabilities in Open5GS