CVE-2025-8800
Last modified
CVE-2025-8800 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A vulnerability has been found in Open5GS up to 2.7.5. Affected by this issue is the function esm_handle_pdn_connectivity_request of the file src/mme/esm-handler.c of the component AMF Component. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in Open5GS up to 2.7.5. Affected by this issue is the function esm_handle_pdn_connectivity_request of the file src/mme/esm-handler.c of the component AMF Component. The manipulation leads to denial of service. The attack may be launched remotely. Upgrading to version 2.7.6 is able to address this issue. The name of the patch is 701505102f514cbde2856cd2ebc9bedb7efc820d. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Open5gs | Open5gs | < 2.7.6 |
References
- https://github.com/open5gs/open5gs/issues/3980Issue Tracking
- https://vuldb.com/?ctiid.319328Permissions Required, VDB Entry
- https://vuldb.com/?id.319328Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.626113Third Party Advisory, VDB Entry
- https://github.com/open5gs/open5gs/issues/3980Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-8800?
How severe is CVE-2025-8800?
How do I fix CVE-2025-8800?
Are you affected by CVE-2025-8800?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
