CVE-2025-5520

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

09 Jun 2025, 15:13

Type Values Removed Values Added
References () https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884 - () https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884 - Patch
References () https://vuldb.com/?submit.582269 - () https://vuldb.com/?submit.582269 - Third Party Advisory, VDB Entry
References () https://github.com/user-attachments/files/20362243/Problematic.handover.required.process.zip - () https://github.com/user-attachments/files/20362243/Problematic.handover.required.process.zip - Exploit
References () https://vuldb.com/?ctiid.310956 - () https://vuldb.com/?ctiid.310956 - Permissions Required, VDB Entry
References () https://github.com/open5gs/open5gs/issues/3910 - () https://github.com/open5gs/open5gs/issues/3910 - Exploit, Issue Tracking
References () https://vuldb.com/?id.310956 - () https://vuldb.com/?id.310956 - Third Party Advisory, VDB Entry
References () https://github.com/open5gs/open5gs/issues/3910#issuecomment-2926719317 - () https://github.com/open5gs/open5gs/issues/3910#issuecomment-2926719317 - Exploit, Issue Tracking
First Time Open5gs open5gs
Open5gs
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

03 Jun 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 18:15

Updated : 2025-06-09 15:13


NVD link : CVE-2025-5520

Mitre link : CVE-2025-5520


JSON object : View

Products Affected

open5gs

  • open5gs
CWE

No CWE.