PT-2026-21563 · Free5Gc · Smf+1

CVE-2025-69232

·

Publicado

2026-02-23

·

Atualizado

2026-02-28

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions free5GC go-upf versions up to and including 1.2.6 free5gc smf versions up to and including 1.4.0
Description The software contains an Improper Input Validation and Protocol Compliance issue that can lead to Denial of Service. Remote attackers can disrupt core network functionality by sending a malformed PFCP Association Setup Request to the UPF. The UPF incorrectly accepts this request, entering an inconsistent state that causes legitimate requests to trigger SMF reconnection loops and service degradation. All deployments of free5GC using the UPF and SMF components may be affected. PFCP stands for Protocol for Control Plane Communication, a protocol used for communication between the SMF and UPF.
Recommendations Apply the official patch once it is released.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69232
GHSA-8M42-QW58-8362

Produtos afetados

Go-Upf
Smf