Vulnerabilidades en Free5Gc

58 resultados
Análisis Vexday

Free5Gc apresenta baixo volume de vulnerabilidades conhecidas (1 CVE), sem registros de exploração ativa. A única vulnerabilidade crítica identificada refere-se a falha de proteção contra CSRF (CWE-352), porém não está em ataque ativo e não foi publicada recentemente, reduzindo a urgência imediata de mitigação.

CVE-2026-55785LOWfree5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKAEPSS 0.4%CVE-2026-27643MEDIUMfree5GC has improper error handling in NEF with information exposureEPSS 0.4%CVE-2023-4659CRITICALCross-Site Request Forgery in Free5GcEPSS 0.4%CVE-2026-44318MEDIUMfree5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on SubscriptionsEPSS 0.4%CVE-2026-44330CRITICALfree5GC: NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptionsEPSS 0.4%CVE-2026-33065MEDIUMfree5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions requestEPSS 0.4%CVE-2026-55784HIGHfree5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPIEPSS 0.4%CVE-2025-69250MEDIUMfree5GC has Improper Error Handling in UDM, Leading to Information ExposureEPSS 0.4%CVE-2026-33192HIGHfree5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions requesEPSS 0.4%CVE-2026-40249MEDIUMfree5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errorsEPSS 0.4%CVE-2026-42082LOWfree5GC: Missing Concurrent NAS SMC Validation During NGAP HandoverEPSS 0.4%CVE-2026-44320HIGHfree5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing pathEPSS 0.4%CVE-2025-69232LOWfree5GC hasProtocol Compliance Violation in UPF Leading to SMF Service DisruptionEPSS 0.4%CVE-2025-69253MEDIUMfree5GC vulnerable to improper error handling in NEF with information exposureEPSS 0.4%CVE-2026-41136MEDIUMfree5GC AMF missing default case in Content-Type switch in HTTPUEContextTransferEPSS 0.3%CVE-2026-40343MEDIUMfree5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creationEPSS 0.3%CVE-2026-42081MEDIUMfree5GC: UE Security Capability bypass on NGAP PathSwitchRequestEPSS 0.3%CVE-2025-69208LOWfree5GC UDR's NEF incorrectly returns 500 for missing PFD data (UDR 404) in Nnef_PfdManagement GET requestEPSS 0.3%