Azure Private 5G Core Denial of Service Vulnerability
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 5.5%
exploitation probability
5.5%top 8% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in Azure Private 5G Core allows an attacker to crash or disable the service by sending specially crafted network messages. This vulnerability can interrupt critical 5G network operations.
Technical detail
CWE-130 (Improper Handling of Length Parameter Inconsistency) in Azure Private 5G Core permits a network-based denial of service attack through malformed input handling. An attacker with network access to the affected component can trigger a service crash by exploiting parameter validation inconsistencies, resulting in unavailability of the 5G core infrastructure.
Summary generated and translated by AI from the official description.
Azure Private 5G Core Denial of Service Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
Affected products
Microsoft · Azure Private 5G Core