Vulnerabilidades en Free5Gc

58 resultados
Análisis Vexday

Free5Gc apresenta baixo volume de vulnerabilidades conhecidas (1 CVE), sem registros de exploração ativa. A única vulnerabilidade crítica identificada refere-se a falha de proteção contra CSRF (CWE-352), porém não está em ataque ativo e não foi publicada recentemente, reduzindo a urgência imediata de mitigação.

CVE-2026-44329CRITICALfree5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlersEPSS 0.6%CVE-2026-32937HIGHfree5GC CHF has Out-of-Bounds Slice Access that Leads to DoSEPSS 0.6%CVE-2025-69247LOWfree5GC has Heap Buffer Overflow in UPF Leading to Denial of ServiceEPSS 0.5%CVE-2026-42083HIGHfree5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPIEPSS 0.5%CVE-2026-44328HIGHfree5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutatingEPSS 0.5%CVE-2026-47780MEDIUMfree5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrary identifier persistenceEPSS 0.5%CVE-2026-41135HIGHfree5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of ServiceEPSS 0.5%CVE-2026-1684MEDIUMFree5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of serviceEPSS 0.5%CVE-2026-44327CRITICALfree5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handlerEPSS 0.5%CVE-2025-69252MEDIUMfree5GC has Null Pointer Dereference in UDM, Leading to Service PanicEPSS 0.5%CVE-2026-44315CRITICALfree5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactionsEPSS 0.5%CVE-2026-44326CRITICALfree5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptionsEPSS 0.5%CVE-2026-26024MEDIUMfree5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE EPSS 0.5%CVE-2026-26025MEDIUMfree5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE EPSS 0.5%CVE-2026-25501MEDIUMfree5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.DLDR is set but DownlinkDataReport IE is missingEPSS 0.5%CVE-2026-40247HIGHfree5gc UDR improper path validation allows unauthenticated access to Traffic Influence SubscriptionsEPSS 0.5%CVE-2026-40248HIGHfree5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence SubscriptionsEPSS 0.5%CVE-2025-69251MEDIUMfree5GC has Improper Input Validation in UDM, Leading to Information ExposureEPSS 0.5%CVE-2026-40246HIGHfree5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence SubscriptionsEPSS 0.4%CVE-2026-42459HIGHfree5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udmEPSS 0.4%