PT-2022-7180 · Free5Gc · Free5Gc
P1-Ajio
·
Published
2022-10-25
·
Updated
2022-10-26
·
CVE-2022-38870
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Free5gc version 3.2.1
Description
The issue is related to information disclosure due to a lack of authentication for a critical function in the free5GC software, which is used for organizing 5G mobile network communications. This allows a remote attacker to disclose protected information.
Recommendations
For Free5gc version 3.2.1, consider implementing authentication for the critical function to prevent information disclosure. As a temporary workaround, restrict access to the critical function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Free5Gc