PT-2026-70962 · Open5Gs · Open5Gs
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.7.2
Description
A remote buffer overflow exists in the Diameter Rx Handler component within the
pcrf rx aar cb() function of the src/pcrf/pcrf-rx-path.c file. This issue occurs when the num of media component or num of sub arguments are manipulated.Recommendations
Upgrade to version 2.7.2.
As a temporary mitigation, restrict access to the Diameter Rx Handler component to minimize the risk of remote exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open5Gs