PT-2026-45091 · Open5Gs · Open5Gs
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.7.8
Description
An out-of-bounds write can be triggered remotely within the Shared NF-profile Parser component. The issue resides in the
handle scp info() function located in the lib/sbi/nnrf-handler.c library.Recommendations
Deploy a patch for versions prior to 2.7.8.
As a temporary workaround, restrict access to the
handle scp info() function to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open5Gs