CVE-2025-6952
A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5.
Does this matter?
Lower severity and a low EPSS score (0.20%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch the attack on the local host. The identifier of the patch is 53e9e059ed96b940f7ddcd9a2b68cb512524d5db. It is recommended to apply a patch to fix this issue.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- open5gs/open5gs
- Source
- cna@vuldb.com
References
- https://github.com/open5gs/open5gs/commit/53e9e059ed96b940f7ddcd9a2b68cb512524d5dbPatch
- https://github.com/open5gs/open5gs/issues/3938Exploit, Issue Tracking, Third Party Advisory
- https://github.com/open5gs/open5gs/issues/3938#issuecomment-3012139813Issue Tracking
- https://vuldb.com/?ctiid.314489Permissions Required, VDB Entry
- https://vuldb.com/?id.314489Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.605312Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.