← Voltar para CVEs
CVE-2025-5520
MEDIUM5.3
Descricao
A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.
Detalhes CVE
Pontuacao CVSS v3.15.3
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado6/3/2025
Ultima modificacao6/9/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
open5gs:open5gs
Fraquezas (CWE)
CWE-617
Referencias
https://github.com/open5gs/open5gs/issues/3910(cna@vuldb.com)
https://github.com/user-attachments/files/20362243/Problematic.handover.required.process.zip(cna@vuldb.com)
https://vuldb.com/?ctiid.310956(cna@vuldb.com)
https://vuldb.com/?id.310956(cna@vuldb.com)
https://vuldb.com/?submit.582269(cna@vuldb.com)
https://github.com/open5gs/open5gs/issues/3910(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.