Vulnerabilidades en Free5Gc

58 resultados
Análisis Vexday

Free5Gc apresenta baixo volume de vulnerabilidades conhecidas (1 CVE), sem registros de exploração ativa. A única vulnerabilidade crítica identificada refere-se a falha de proteção contra CSRF (CWE-352), porém não está em ataque ativo e não foi publicada recentemente, reduzindo a urgência imediata de mitigação.

CVE-2026-40343MEDIUMfree5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creationEPSS 8.6%CVE-2026-1739MEDIUMFree5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereferenceEPSS 0.7%CVE-2026-1682MEDIUMFree5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferenceEPSS 0.7%CVE-2026-1683MEDIUMFree5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of serviceEPSS 0.7%CVE-2026-33062HIGHfree5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list ParameterEPSS 0.7%CVE-2026-33063HIGHfree5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface ConversionEPSS 0.7%CVE-2025-69248MEDIUMfree5GC has Array Index Out of Bounds in AMF Leading to Denial of ServiceEPSS 0.6%CVE-2026-53551MEDIUMfree5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failureEPSS 0.5%CVE-2026-1684MEDIUMFree5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of serviceEPSS 0.5%CVE-2025-69247LOWfree5GC has Heap Buffer Overflow in UPF Leading to Denial of ServiceEPSS 0.5%CVE-2026-41135HIGHfree5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of ServiceEPSS 0.5%CVE-2025-69252MEDIUMfree5GC has Null Pointer Dereference in UDM, Leading to Service PanicEPSS 0.5%CVE-2026-27642MEDIUMfree5GC has Improper Input Validation in UDM UEAU ServiceEPSS 0.5%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.5%CVE-2026-40247HIGHfree5gc UDR improper path validation allows unauthenticated access to Traffic Influence SubscriptionsEPSS 0.5%CVE-2026-33064HIGHfree5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer DereferenceEPSS 0.5%CVE-2025-69251MEDIUMfree5GC has Improper Input Validation in UDM, Leading to Information ExposureEPSS 0.5%CVE-2026-55068CRITICALfree5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpointsEPSS 0.4%CVE-2023-4659CRITICALCross-Site Request Forgery in Free5GcEPSS 0.4%CVE-2026-40248HIGHfree5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence SubscriptionsEPSS 0.4%