SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-28122

The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database.

CRITICAL 9.8EPSS 3.96%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
3.96% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
open5gs/open5gs
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.