VulnerabilityModified
CVE-2026-1683
A vulnerability has been found in Free5GC SMF up to 4.1.0.
MEDIUM 5.5EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. To fix this issue, it is recommended to deploy a patch.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-404
- Affected
- free5gc/free5gc
- Source
- cna@vuldb.com
References
- https://github.com/free5gc/free5gc/issues/804Exploit, Issue Tracking
- https://github.com/free5gc/free5gc/issues/804#issue-3816086696Exploit, Issue Tracking, Vendor Advisory
- https://github.com/free5gc/smf/
- https://github.com/free5gc/smf/pull/188Issue Tracking
- https://vuldb.com/?ctiid.343476Permissions Required, VDB Entry
- https://vuldb.com/?id.343476Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.739653Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.739654Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.