Sceawere
Vulnerability Detail
CVE-2025-15687UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Open5GS SMF Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- n/a
- Product
- Open5GS
- Attack Type
- Denial of Service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-08-12T04:17:38.617Z",
"pubdate": "2026-08-12T04:17:38.617Z",
"executiveSummary": "A denial of service vulnerability has been identified in Open5GS up to version 2.7.6, specifically within the SMF Diameter Gx Credit-Control-Answer Handler component. The vulnerability resides in the function smf_gx_cca_cb.\nManipulation of this component through crafted Diameter signaling enables remote threat actors to trigger a denial of service condition, disrupting core network operations.\nThe risk implication is severe as it affects core 5G Session Management Function (SMF) availability, potentially causing service outages for attached user equipment.\nAttack capabilities include remote launching of the exploit without requiring prior authentication or elevated privileges, provided the attacker can interact with the affected network interfaces.\nPublic exploits are available, increasing the likelihood of active exploitation in the wild.\nImmediate remediation is required to maintain network resilience.",
"technicalDetails": "The vulnerability is localized to the Session Management Function (SMF) of Open5GS, specifically within the Diameter Gx interface handler function designated as smf_gx_cca_cb.\nThe root cause stems from improper handling or validation of incoming Diameter Credit-Control-Answer (CCA) messages received by the SMF Gx application.\nAffected software versions include Open5GS up to and including version 2.7.6.\nThe attack vector is network-based, allowing remote adversaries to launch attacks against the vulnerable SMF component without authentication or privileged access.\nThe step-by-step attack flow begins with an attacker establishing or leveraging network connectivity to the Diameter Gx interface exposed by the Open5GS SMF.\nThe attacker crafts a malicious or malformed Diameter Gx Credit-Control-Answer (CCA) message designed to trigger abnormal execution flow or memory handling errors within the smf_gx_cca_cb function.\nUpon receipt and processing of the malicious payload by the SMF, the lack of robust input validation or error handling within smf_gx_cca_cb leads to an unhandled exception, assertion failure, or application crash.\nThe resulting crash terminates the SMF daemon processes, resulting in a complete denial of service for session management operations across the 5G core network.\nPost-exploitation impact is constrained to availability disruption, preventing new session establishments and destabilizing existing user plane connectivity due to the loss of the SMF component."
}