Denial of Service Vulnerability in Open5GS by Open5GS Team
CVE-2025-29646

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
18 June 2025

What is CVE-2025-29646?

A vulnerability in Open5GS versions 2.7.2 and earlier permits remote attackers to initiate a Denial of Service. This is achieved by sending a specially crafted PFCP SessionEstablishmentRequest packet that indicates restoration is requested, alongside specific TEID values. Exploiting this flaw can disrupt the service's normal operation, potentially impacting users and applications relying on its functionality.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.