Записи Open5GS
154 опубликованных записей вендора open5gs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 4,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-404 Improper Resource Shutdown or Release64
- CWE-617 Reachable Assertion46
- CWE-400 Uncontrolled Resource Consumption11
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-787 Out-of-bounds Write4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
154 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-28122Эксплойта нет | A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1.open5gs · open5gs · CWE-306 | Критическая9,8 | — | 4,0 % | 10 мар. 2021 г. |
39Наблюдать | CVE-2024-40130Эксплойта нет | open5gs v2.6.4 is vulnerable to Buffer Overflow.open5gs · open5gs · CWE-787 | Критическая9,8 | — | 0,6 % | 16 июл. 2024 г. |
39Наблюдать | CVE-2024-40129Эксплойта нет | Open5GS v2.6.4 is vulnerable to Buffer Overflow.open5gs · open5gs · CWE-787 | Критическая9,8 | — | 0,5 % | 16 июл. 2024 г. |
35Наблюдать | CVE-2021-25863Эксплойта нет | Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.open5gs · open5gs · CWE-287 | Высокая8,8 | — | 1,2 % | 26 янв. 2021 г. |
34Наблюдать | CVE-2023-37021Эксплойта нет | Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37023Эксплойта нет | Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37019Эксплойта нет | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37016Эксплойта нет | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37020Эксплойта нет | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37017Эксплойта нет | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37015Эксплойта нет | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2024-34235Эксплойта нет | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37018Эксплойта нет | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2024-24429Эксплойта нет | A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,6 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2025-41067Proof of concept | Reachable Assertion vulnerability in Open5GSopen5gs · open5gs · CWE-617 | Высокая8,7 | — | 0,4 % | 27 окт. 2025 г. |
34Наблюдать | CVE-2025-41068Эксплойта нет | Reachable Assertion vulnerability in Open5GSopen5gs · open5gs · CWE-617 | Высокая8,7 | — | 0,4 % | 27 окт. 2025 г. |
31Наблюдать | CVE-2021-45462Эксплойта нет | In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.open5gs · open5gs · CWE-1284 | Высокая7,5 | — | 4,4 % | 23 дек. 2021 г. |
31Наблюдать | CVE-2025-44952Эксплойта нет | A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a open5gs · open5gs · CWE-120 | Высокая7,8 | — | 0,2 % | 18 июн. 2025 г. |
30Наблюдать | CVE-2021-44109Эксплойта нет | A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.open5gs · open5gs · CWE-787 | Высокая7,5 | — | 1,6 % | 4 апр. 2022 г. |
30Наблюдать | CVE-2021-44108Эксплойта нет | A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a craftedopen5gs · open5gs · CWE-476 | Высокая7,5 | — | 1,5 % | 4 апр. 2022 г. |
30Наблюдать | CVE-2021-41794Эксплойта нет | ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow.open5gs · open5gs · CWE-120 | Высокая7,5 | — | 1,2 % | 7 окт. 2021 г. |
30Наблюдать | CVE-2022-39063Эксплойта нет | When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Responsopen5gs · open5gs · CWE-676 | Высокая7,5 | — | 1,2 % | 16 сент. 2022 г. |
30Наблюдать | CVE-2024-51179Proof of concept | An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as topen5gs · open5gs · CWE-404 | Высокая7,5 | — | 1,1 % | 12 нояб. 2024 г. |
30Наблюдать | CVE-2021-44081Эксплойта нет | A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4.open5gs · open5gs · CWE-787 | Высокая7,5 | — | 1,0 % | 29 мар. 2022 г. |
30Наблюдать | CVE-2022-40890Эксплойта нет | A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.open5gs · open5gs · CWE-404 | Высокая7,5 | — | 1,0 % | 29 сент. 2022 г. |
- CVE-2021-2812240В плане
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %open5gs · open5gs10 мар. 2021 г.
- CVE-2024-4013039Наблюдать
open5gs v2.6.4 is vulnerable to Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %open5gs · open5gs16 июл. 2024 г.
- CVE-2024-4012939Наблюдать
Open5GS v2.6.4 is vulnerable to Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %open5gs · open5gs16 июл. 2024 г.
- CVE-2021-2586335Наблюдать
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %open5gs · open5gs26 янв. 2021 г.
- CVE-2023-3702134Наблюдать
Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3702334Наблюдать
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701934Наблюдать
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701634Наблюдать
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3702034Наблюдать
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701734Наблюдать
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701534Наблюдать
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2024-3423534Наблюдать
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701834Наблюдать
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2024-2442934Наблюдать
A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2025-4106734Наблюдать
Reachable Assertion vulnerability in Open5GS
ВысокаяCVSS 8,7Proof of conceptEPSS 0 %open5gs · open5gs27 окт. 2025 г.
- CVE-2025-4106834Наблюдать
Reachable Assertion vulnerability in Open5GS
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %open5gs · open5gs27 окт. 2025 г.
- CVE-2021-4546231Наблюдать
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %open5gs · open5gs23 дек. 2021 г.
- CVE-2025-4495231Наблюдать
A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %open5gs · open5gs18 июн. 2025 г.
- CVE-2021-4410930Наблюдать
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %open5gs · open5gs4 апр. 2022 г.
- CVE-2021-4410830Наблюдать
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %open5gs · open5gs4 апр. 2022 г.
- CVE-2021-4179430Наблюдать
ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %open5gs · open5gs7 окт. 2021 г.
- CVE-2022-3906330Наблюдать
When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Respons
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %open5gs · open5gs16 сент. 2022 г.
- CVE-2024-5117930Наблюдать
An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as t
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %open5gs · open5gs12 нояб. 2024 г.
- CVE-2021-4408130Наблюдать
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %open5gs · open5gs29 мар. 2022 г.
- CVE-2022-4089030Наблюдать
A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %open5gs · open5gs29 сент. 2022 г.