Sceawere
Vulnerability Detail
CVE-2025-15685UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Open5GS freeDiameter Memory Corruption Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 3h ago
- Vendor
- n/a
- Product
- Open5GS
- Attack Type
- Memory Corruption
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-08-12T03:16:42.420Z",
"pubdate": "2026-08-12T03:16:42.420Z",
"executiveSummary": "A memory corruption vulnerability has been identified in Open5GS up to version 2.7.1, specifically within the freeDiameter component. This vulnerability allows remote threat actors to manipulate unknown functionality, leading to severe memory corruption conditions. The flaw poses significant risk implications to affected 5G core network deployments, potentially resulting in denial of service or arbitrary code execution depending on the runtime environment. The attack vector is fully remote, requiring network connectivity to the vulnerable DIAMETER interface without explicit prerequisites such as prior authentication or high-level privileges mentioned in the advisory. Exploitation compromises the stability and integrity of the affected signaling plane components, necessitating immediate attention from network operators.",
"technicalDetails": "The vulnerability resides within the freeDiameter component utilized by Open5GS up to version 2.7.1 for DIAMETER protocol signaling and AAA operations. The root cause stems from improper handling or parsing of incoming DIAMETER messages or state management within the affected subcomponent, resulting in a memory corruption condition such as a buffer overflow, use-after-free, or heap corruption.\nAttack execution occurs over the network layer where DIAMETER communications are processed. A remote attacker sends a maliciously crafted packet or sequence of payloads directed at the vulnerable freeDiameter interface exposed by Open5GS network functions (such as the HSS, PCRF, or AMF/SMF depending on architecture). Upon receipt, the vulnerable component fails to adequately validate input boundaries, length specifiers, or internal object lifecycles during the parsing phase.\nAs the malformed payload is processed by the application logic, memory is incorrectly allocated, read, written, or freed, directly corrupting adjacent heap or stack structures. Depending on the exact nature of the corrupted memory region, this state can cause immediate application crashes leading to a denial of service (DoS) condition, or potentially be leveraged for remote code execution (RCE) if control data structures are overwritten.\nThe affected versions include all Open5GS releases up to and including 2.7.1. Exploitation requires network exposure of the DIAMETER service ports, typically TCP/SCTP port 3868 or configured alternatives, but does not inherently require pre-existing authentication credentials or elevated local privileges, thereby widening the attack surface for external threat actors able to reach the signaling interfaces."
}