Denial of Service Vulnerability in Open5GS AMF Component
CVE-2025-1925
Key Information:
Badges
What is CVE-2025-1925?
A critical vulnerability has been identified in the AMF component of Open5GS, specifically within the function responsible for handling updates to the PDU session context. This flaw allows an attacker to remotely provoke a denial of service condition, resulting in the complete disruption of mobility and session management services. When exploited, a single End User (UE) can crash the AMF, causing all registered UEs to lose network connectivity. Furthermore, any new registration attempts will be denied until the AMF is restarted. Given the ramifications of this vulnerability, which includes widespread network outages, it is imperative that users apply the recommended patches to safeguard their systems.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved