HomeOpen5gsCVE-2025-55904

CVE-2025-55904

MEDIUM
4.0CVSS
Published: 2025-09-17
Updated: 2025-09-23
AI Analysis

Description

Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference when a multipart/related HTTP POST request with an empty HTTP body is sent to the SBI of either AMF, AUSF, BSF, NRF, NSSF, PCF, SMF, UDM, or UDR, resulting in a denial of service. This occurs in the parse_multipart function in lib/sbi/message.c.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
local
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
none
Availability
low
Weaknesses
CWE-476

Metadata

Primary Vendor
OPEN5GS
Published
9/17/2025
Last Modified
9/23/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

open5gs : open5gs

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-55904 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com