Denial of Service Vulnerability in Open5GS by Open5GS
CVE-2025-8803
6.9MEDIUM
What is CVE-2025-8803?
A remote denial of service vulnerability has been identified in the Open5GS Access and Mobility Management Function (AMF), specifically in the gmm_state_de_registered and gmm_state_exception functions. This flaw allows attackers to disrupt service and affect application performance. The issue has been addressed in version 2.7.6, and users are strongly encouraged to upgrade their installations to avoid potential service interruptions. The corresponding patch can be found in commit 1f30edac27f69f61cff50162e980fe58fdeb30ca.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
xiaohan zheng (VulDB User)
