在 Open5GS 2.8.0 及更早版本中,mme_gn_handle_sgsn_context_request() 函数存在一个可触发的断言(assertion)漏洞,远程未认证攻击者可通过构造恶意的 SGSN 地址信息元素(IEs)使 MME(移动管理实体)崩溃。攻击者若已知用户的 IMSI 或 P-TMSI,可从配置的 SGSN 地址发送 GTPv1-C 流量,并提供无效的地址长度,从而导致 open5gs-mmed 进程终止,进而使所有用户的服务不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108102 | 5.3 MEDIUM | Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Volume Measurement IE |
| CVE-2026-108103 | 5.3 MEDIUM | Open5GS through 2.8.0 Heap Out-of-Bounds Read via PFCP Dropped DL Traffic Threshold IE |
No comments yet