Vulnerabilities > Open5Gs

DATE CVE VULNERABILITY TITLE RISK
2022-09-29 CVE-2022-40890 Improper Resource Shutdown or Release vulnerability in Open5Gs
A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
network
low complexity
open5gs CWE-404
7.5
2022-09-28 CVE-2022-3354 Improper Resource Shutdown or Release vulnerability in Open5Gs
A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic.
network
low complexity
open5gs CWE-404
7.5
2022-09-26 CVE-2022-3299 Improper Resource Shutdown or Release vulnerability in Open5Gs
A vulnerability was found in Open5GS up to 2.4.10.
network
low complexity
open5gs CWE-404
6.5
2022-04-05 CVE-2021-44108 NULL Pointer Dereference vulnerability in Open5Gs
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.
network
low complexity
open5gs CWE-476
5.0
2022-04-05 CVE-2021-44109 Out-of-bounds Write vulnerability in Open5Gs
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
network
low complexity
open5gs CWE-787
5.0
2022-03-29 CVE-2021-44081 Out-of-bounds Write vulnerability in Open5Gs 2.1.4
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4.
network
low complexity
open5gs CWE-787
5.0
2021-12-23 CVE-2021-45462 Improper Validation of Specified Quantity in Input vulnerability in Open5Gs 2.4.0
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
network
low complexity
open5gs CWE-1284
7.5
2021-10-07 CVE-2021-41794 Classic Buffer Overflow vulnerability in Open5Gs
ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow.
network
low complexity
open5gs CWE-120
5.0
2021-03-10 CVE-2021-28122 Missing Authentication for Critical Function vulnerability in Open5Gs
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1.
network
low complexity
open5gs CWE-306
7.5
2021-01-26 CVE-2021-25863 Improper Authentication vulnerability in Open5Gs 2.1.3
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
low complexity
open5gs CWE-287
8.8