PT-2026-70972 · Open5Gs · Open5Gs
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
Open5GS versions prior to 2.7.7
Description
A remote attack can trigger a reachable assertion within the CER Handler component. The issue resides in the
diam log func() function located in the lib/diameter/common/init.c file.Recommendations
Upgrade to version 2.7.7.
As a temporary mitigation, restrict access to the CER Handler component to minimize the risk of remote exploitation.
Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open5Gs