CVE-2025-7485 Information
Description
A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial Message Handler. The manipulation leads to reachable assertion. The attack needs to be approached locally. The patch is named cfa44575020f3fb045fd971358442053c8684d3d. It is recommended to apply a patch to fix this issue.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Reference
https://github.com/open5gs/open5gs/commit/cfa44575020f3fb045fd971358442053c8684d3d https://github.com/open5gs/open5gs/issues/3878#issuecomment-2853775136 https://github.com/open5gs/open5gs/issues/3878/ https://vuldb.com/?ctiid.316135 https://vuldb.com/?id.316135 https://vuldb.com/?submit.610601
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
3.3
Related CNNVD
CNNVD-202507-1746 (Published: 2025-07-12)
Share on: