PT-2025-9575 · Open5Gs · Open5Gs
Enginerstaticpower
+6
·
Published
2025-03-04
·
Updated
2025-06-03
·
CVE-2025-1893
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Open5GS versions up to 2.7.2
Description
A denial of service issue has been found in the
gmm state authentication function of the file src/amf/gmm-sm.c in the component AMF. This issue can be exploited remotely, leading to a network-wide outage, causing all registered UEs to lose connectivity, and blocking new registrations until the AMF is restarted. The exploit has been disclosed to the public and may be used.Recommendations
To fix this issue, apply the patch named
e31e9965f00d9c744a7f728497cb4f3e97744ee8 to the affected Open5GS version.
As a temporary workaround, consider restricting access to the gmm state authentication function until a patch is available.Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open5Gs