Vulnerabilidades en free5gc
58 resultadosAnálisis Vexday
Free5gc apresenta 48 vulnerabilidades catalogadas, com 20 divulgadas nos últimos 90 dias, indicando ritmo significativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), 5 são críticas, sendo CWE-476 (null pointer dereference) o padrão predominante, sugerindo falhas sistemáticas em validação de entrada que demandam atenção imediata para implementações em produção.
CVE-2026-55785LOWfree5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKAEPSS 0.4%CVE-2026-27643MEDIUMfree5GC has improper error handling in NEF with information exposureEPSS 0.4%CVE-2023-4659CRITICALCross-Site Request Forgery in Free5GcEPSS 0.4%CVE-2026-44318MEDIUMfree5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on SubscriptionsEPSS 0.4%CVE-2026-44330CRITICALfree5GC: NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptionsEPSS 0.4%CVE-2026-33065MEDIUMfree5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions requestEPSS 0.4%CVE-2026-55784HIGHfree5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPIEPSS 0.4%CVE-2025-69250MEDIUMfree5GC has Improper Error Handling in UDM, Leading to Information ExposureEPSS 0.4%CVE-2026-33192HIGHfree5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions requesEPSS 0.4%CVE-2026-40249MEDIUMfree5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errorsEPSS 0.4%CVE-2026-42082LOWfree5GC: Missing Concurrent NAS SMC Validation During NGAP HandoverEPSS 0.4%CVE-2026-44320HIGHfree5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing pathEPSS 0.4%CVE-2025-69232LOWfree5GC hasProtocol Compliance Violation in UPF Leading to SMF Service DisruptionEPSS 0.4%CVE-2025-69253MEDIUMfree5GC vulnerable to improper error handling in NEF with information exposureEPSS 0.4%CVE-2026-41136MEDIUMfree5GC AMF missing default case in Content-Type switch in HTTPUEContextTransferEPSS 0.3%CVE-2026-40343MEDIUMfree5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creationEPSS 0.3%CVE-2026-42081MEDIUMfree5GC: UE Security Capability bypass on NGAP PathSwitchRequestEPSS 0.3%CVE-2025-69208LOWfree5GC UDR's NEF incorrectly returns 500 for missing PFD data (UDR 404) in Nnef_PfdManagement GET requestEPSS 0.3%