PT-2026-21582 · Free5Gc · Free5Gc
CVE-2025-69253
·
Publicado
2026-02-24
·
Atualizado
2026-02-25
CVSS v4.0
6.6
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
free5GC versions up to and including 1.4.1
Description
free5GC is an open-source project for 5G mobile core networks. Improper error handling with information exposure exists in the User Data Repository component. The NEF component leaks internal parsing error details to remote clients, potentially aiding attackers in service fingerprinting. Deployments using the Nnef PfdManagement service may be vulnerable.
Recommendations
Apply the patch available in free5gc/udr pull request 56.
Exploit
Correção
Generation of Error Message Containing Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Free5Gc