CVE-2025-15687
LOW
2,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low
MEDIUM
4,0
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: none
Integrity: none
Availability: partial
Description
AI Translation Available
A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.
404
Improper Resource Shutdown or Release
DraftCommon Consequences
Security Scopes Affected:
Availability
Other
Confidentiality
Potential Impacts:
Dos: Resource Consumption (Other)
Varies By Context
Read Application Data
Applicable Platforms
All platforms may be affected
https://github.com/open5gs/open5gs/
https://github.com/open5gs/open5gs/commit/f23d7a5e959acd8f37b925dc29b85f26b7d39…
https://github.com/open5gs/open5gs/issues/4027
https://github.com/open5gs/open5gs/pull/4034
https://github.com/open5gs/open5gs/releases/tag/v2.7.7
https://github.com/user-attachments/files/21515527/SMF.crashes.zip
https://vuldb.com/cve/CVE-2025-15687
https://vuldb.com/submit/867119
https://vuldb.com/vuln/387283
https://vuldb.com/vuln/387283/cti