CVE-2025-15529 is a denial-of-service vulnerability affecting Open5GS versions up to 2.7.6, specifically within the sgwc_s5c_handle_create_session_response function in src/sgwc/s5c-handler.c. This flaw carries a high CVSS score of 7.5, indicating it can be exploited remotely without authentication or user interaction, leading to a complete loss of availability for affected systems. While not currently on the CISA KEV catalog, public exploit code exists, and the vulnerability has garnered significant community discussion, suggesting a heightened risk of exploitation. A patch (b19cf6a2dbf5d30811be4488bf059c865bd7d1d2) is available to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7.6CPE matchmatch criteria | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.