PT-2026-21593 · Free5Gc · Free5Gc
Zfei10990-Cmd
·
Published
2026-02-24
·
Updated
2026-02-25
·
CVE-2026-27643
CVSS v4.0
6.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
free5GC versions prior to 1.4.2
Description
The free5GC UDR component, a user data repository for 5G mobile core networks, exhibits an information disclosure issue. The NEF component reveals internal parsing error details to remote clients, potentially aiding attackers in service fingerprinting. This affects all deployments of free5GC utilizing the Nnef PfdManagement service. The issue stems from the reliable leakage of parsing errors, such as invalid characters, to external entities.
Recommendations
Apply the patch available in free5gc/udr pull request 56.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Free5Gc