PT-2026-70942 · Open5Gs · Open5Gs
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.7.2
Description
A heap-based buffer overflow exists in the Diameter S6a Interface component within the
mme s6a subscription data from avp() function of the src/mme/mme-fd-path.c file. This issue can be triggered remotely by manipulating the msisdn len argument.Recommendations
Update to version 2.7.2.
As a temporary mitigation, restrict access to the Diameter S6a Interface component to minimize the risk of remote exploitation.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open5Gs