Open5GS kayıtları
open5gs üreticisine ait 154 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %4,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-404 Improper Resource Shutdown or Release64
- CWE-617 Reachable Assertion46
- CWE-400 Uncontrolled Resource Consumption11
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-787 Out-of-bounds Write4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
154 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-28122İstismar yok | A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1.open5gs · open5gs · CWE-306 | Kritik9,8 | — | %4,0 | 10 Mar 2021 |
39İzleyin | CVE-2024-40130İstismar yok | open5gs v2.6.4 is vulnerable to Buffer Overflow.open5gs · open5gs · CWE-787 | Kritik9,8 | — | %0,6 | 16 Tem 2024 |
39İzleyin | CVE-2024-40129İstismar yok | Open5GS v2.6.4 is vulnerable to Buffer Overflow.open5gs · open5gs · CWE-787 | Kritik9,8 | — | %0,5 | 16 Tem 2024 |
35İzleyin | CVE-2021-25863İstismar yok | Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.open5gs · open5gs · CWE-287 | Yüksek8,8 | — | %1,2 | 26 Oca 2021 |
34İzleyin | CVE-2023-37021İstismar yok | Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2023-37023İstismar yok | Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2023-37019İstismar yok | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2023-37016İstismar yok | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2023-37020İstismar yok | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2023-37017İstismar yok | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2023-37015İstismar yok | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2024-34235İstismar yok | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2023-37018İstismar yok | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,8 | 22 Oca 2025 |
34İzleyin | CVE-2024-24429İstismar yok | A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a open5gs · open5gs · CWE-617 | Yüksek8,6 | — | %0,6 | 22 Oca 2025 |
34İzleyin | CVE-2025-41067Kavram kanıtı | Reachable Assertion vulnerability in Open5GSopen5gs · open5gs · CWE-617 | Yüksek8,7 | — | %0,4 | 27 Eki 2025 |
34İzleyin | CVE-2025-41068İstismar yok | Reachable Assertion vulnerability in Open5GSopen5gs · open5gs · CWE-617 | Yüksek8,7 | — | %0,4 | 27 Eki 2025 |
31İzleyin | CVE-2021-45462İstismar yok | In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.open5gs · open5gs · CWE-1284 | Yüksek7,5 | — | %4,4 | 23 Ara 2021 |
31İzleyin | CVE-2025-44952İstismar yok | A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a open5gs · open5gs · CWE-120 | Yüksek7,8 | — | %0,2 | 18 Haz 2025 |
30İzleyin | CVE-2021-44109İstismar yok | A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.open5gs · open5gs · CWE-787 | Yüksek7,5 | — | %1,6 | 4 Nis 2022 |
30İzleyin | CVE-2021-44108İstismar yok | A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a craftedopen5gs · open5gs · CWE-476 | Yüksek7,5 | — | %1,5 | 4 Nis 2022 |
30İzleyin | CVE-2021-41794İstismar yok | ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow.open5gs · open5gs · CWE-120 | Yüksek7,5 | — | %1,2 | 7 Eki 2021 |
30İzleyin | CVE-2022-39063İstismar yok | When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Responsopen5gs · open5gs · CWE-676 | Yüksek7,5 | — | %1,2 | 16 Eyl 2022 |
30İzleyin | CVE-2024-51179Kavram kanıtı | An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as topen5gs · open5gs · CWE-404 | Yüksek7,5 | — | %1,1 | 12 Kas 2024 |
30İzleyin | CVE-2021-44081İstismar yok | A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4.open5gs · open5gs · CWE-787 | Yüksek7,5 | — | %1,0 | 29 Mar 2022 |
30İzleyin | CVE-2022-40890İstismar yok | A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.open5gs · open5gs · CWE-404 | Yüksek7,5 | — | %1,0 | 29 Eyl 2022 |
- CVE-2021-2812240Planlayın
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1.
KritikCVSS 9,8İstismar yokEPSS %4open5gs · open5gs10 Mar 2021
- CVE-2024-4013039İzleyin
open5gs v2.6.4 is vulnerable to Buffer Overflow.
KritikCVSS 9,8İstismar yokEPSS %1open5gs · open5gs16 Tem 2024
- CVE-2024-4012939İzleyin
Open5GS v2.6.4 is vulnerable to Buffer Overflow.
KritikCVSS 9,8İstismar yokEPSS %0open5gs · open5gs16 Tem 2024
- CVE-2021-2586335İzleyin
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
YüksekCVSS 8,8İstismar yokEPSS %1open5gs · open5gs26 Oca 2021
- CVE-2023-3702134İzleyin
Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2023-3702334İzleyin
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2023-3701934İzleyin
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2023-3701634İzleyin
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2023-3702034İzleyin
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2023-3701734İzleyin
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2023-3701534İzleyin
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2024-3423534İzleyin
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2023-3701834İzleyin
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2024-2442934İzleyin
A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a
YüksekCVSS 8,6İstismar yokEPSS %1open5gs · open5gs22 Oca 2025
- CVE-2025-4106734İzleyin
Reachable Assertion vulnerability in Open5GS
YüksekCVSS 8,7Kavram kanıtıEPSS %0open5gs · open5gs27 Eki 2025
- CVE-2025-4106834İzleyin
Reachable Assertion vulnerability in Open5GS
YüksekCVSS 8,7İstismar yokEPSS %0open5gs · open5gs27 Eki 2025
- CVE-2021-4546231İzleyin
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
YüksekCVSS 7,5İstismar yokEPSS %4open5gs · open5gs23 Ara 2021
- CVE-2025-4495231İzleyin
A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and earlier, allows a
YüksekCVSS 7,8İstismar yokEPSS %0open5gs · open5gs18 Haz 2025
- CVE-2021-4410930İzleyin
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
YüksekCVSS 7,5İstismar yokEPSS %2open5gs · open5gs4 Nis 2022
- CVE-2021-4410830İzleyin
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted
YüksekCVSS 7,5İstismar yokEPSS %1open5gs · open5gs4 Nis 2022
- CVE-2021-4179430İzleyin
ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow.
YüksekCVSS 7,5İstismar yokEPSS %1open5gs · open5gs7 Eki 2021
- CVE-2022-3906330İzleyin
When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session Establishment Respons
YüksekCVSS 7,5İstismar yokEPSS %1open5gs · open5gs16 Eyl 2022
- CVE-2024-5117930İzleyin
An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as t
YüksekCVSS 7,5Kavram kanıtıEPSS %1open5gs · open5gs12 Kas 2024
- CVE-2021-4408130İzleyin
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4.
YüksekCVSS 7,5İstismar yokEPSS %1open5gs · open5gs29 Mar 2022
- CVE-2022-4089030İzleyin
A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
YüksekCVSS 7,5İstismar yokEPSS %1open5gs · open5gs29 Eyl 2022