CVE-2025-7485 Information

Description

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial Message Handler. The manipulation leads to reachable assertion. The attack needs to be approached locally. The patch is named cfa44575020f3fb045fd971358442053c8684d3d. It is recommended to apply a patch to fix this issue.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Reference

https://github.com/open5gs/open5gs/commit/cfa44575020f3fb045fd971358442053c8684d3d https://github.com/open5gs/open5gs/issues/3878#issuecomment-2853775136 https://github.com/open5gs/open5gs/issues/3878/ https://vuldb.com/?ctiid.316135 https://vuldb.com/?id.316135 https://vuldb.com/?submit.610601

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

3.3

CNNVD-202507-1746 (Published: 2025-07-12)

Share on: