PT-2021-24241 · Open5Gs · Open5Gs

Salim S.I

·

Published

2021-12-23

·

Updated

2023-09-25

·

CVE-2021-45462

CVSS v3.1

7.5

High

VectorAC:L/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions: Open5GS version 2.4.0
Description: A crafted packet from a UE can cause a crash in the SGW-U/UPF component. This issue can potentially be used to deploy a denial-of-service (DoS) attack on private 5G networks.
Recommendations: For Open5GS version 2.4.0, consider implementing packet validation and filtering to prevent malicious packets from reaching the SGW-U/UPF component. As a temporary workaround, restrict access to the SGW-U/UPF component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2021-45462

Affected Products

Open5Gs