HomeOpen5gsCVE-2025-29646

CVE-2025-29646

HIGH
7.1CVSS
Published: 2025-06-18
Updated: 2025-07-09
AI Analysis

Description

An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
low
Availability
none
Weaknesses
CWE-20

Metadata

Primary Vendor
OPEN5GS
Published
6/18/2025
Last Modified
7/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

open5gs : open5gs

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-29646 | HIGH Severity | CVEDatabase.com | CVEDatabase.com