CVE-2025-5520

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.
Configurations

No configuration.

History

04 Jun 2025, 14:54

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en Open5GS hasta la versión 2.7.3. Se ha clasificado como problemática. La función gmm_state_authentication/emm_state_authentication del componente AMF/MME está afectada. La manipulación genera una aserción accesible. Es posible lanzar el ataque de forma remota. Se ha hecho público el exploit y puede que sea utilizado. El parche se llama 9f5d133657850e6167231527514ee1364d37a884. Se recomienda aplicar un parche para solucionar este problema. Este problema es diferente al de CVE-2025-1893.

03 Jun 2025, 19:15

Type Values Removed Values Added
References () https://github.com/open5gs/open5gs/issues/3910 - () https://github.com/open5gs/open5gs/issues/3910 -

03 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 18:15

Updated : 2025-06-04 14:54


NVD link : CVE-2025-5520

Mitre link : CVE-2025-5520

CVE.ORG link : CVE-2025-5520


JSON object : View

Products Affected

No product.

CWE
CWE-617

Reachable Assertion