CVE-2022-39063 is a critical vulnerability affecting Open5GS UPF, where a specially crafted PFCP Session Establishment Request can lead to a segmentation fault. The flaw stems from improper length validation during data copying, allowing an attacker to overwrite critical memory fields. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, resulting in a denial-of-service condition. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.9CPE matchmatch criteria | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.