CVE-2025-8801
A vulnerability was found in Open5GS up to 2.7.5.
Does this matter?
Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Open5GS up to 2.7.5. This affects the function gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.7.6 is able to address this issue. The identifier of the patch is f47f2bd4f7274295c5fbb19e2f806753d183d09a. It is recommended to upgrade the affected component.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- open5gs/open5gs
- Source
- cna@vuldb.com
References
- https://github.com/ZHENGHAOHELLO/BugReport/blob/main/CVE-2025-8801
- https://github.com/open5gs/open5gs/commit/f47f2bd4f7274295c5fbb19e2f806753d183d09aPatch
- https://github.com/open5gs/open5gs/issues/3977Issue Tracking
- https://github.com/open5gs/open5gs/issues/3977#issuecomment-3052575886Issue Tracking
- https://github.com/open5gs/open5gs/releases/tag/v2.7.6Release Notes
- https://github.com/user-attachments/files/21095572/nudm-sdm.zipExploit
- https://vuldb.com/?ctiid.319329Permissions Required, VDB Entry
- https://vuldb.com/?id.319329Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.626118Third Party Advisory, VDB Entry
- https://github.com/open5gs/open5gs/issues/3977Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.