PT-2026-21593 · Free5Gc · Free5Gc

Zfei10990-Cmd

·

Publicado

2026-02-24

·

Atualizado

2026-02-25

·

CVE-2026-27643

CVSS v4.0

6.6

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions free5GC versions prior to 1.4.2
Description The free5GC UDR component, a user data repository for 5G mobile core networks, exhibits an information disclosure issue. The NEF component reveals internal parsing error details to remote clients, potentially aiding attackers in service fingerprinting. This affects all deployments of free5GC utilizing the Nnef PfdManagement service. The issue stems from the reliable leakage of parsing errors, such as invalid characters, to external entities.
Recommendations Apply the patch available in free5gc/udr pull request 56.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27643
GHSA-6468-F87J-6G82

Produtos afetados

Free5Gc