free5GC 是 5G 核心网的开源实现。在 1.4.5 版本之前,AUSF 组件在 中使用普通的相等性辅助函数进行加密认证比对。 具体表现为: 使用 比对 RES 和 XRES,并在比对前以 INFO 级别日志记录了预期的 XRES 值。 使用 比对 AT_MAC 和 XMAC,并使用普通字符串相等性判断 XRES == RES。 这些比较操作在结果不匹配时可能返回时间不同,但由于 HTTP/SBI 时序噪声的存在,测试并未证明存在实际可利用的远程时序预言机(timing oracle)。 此外,INFO 级别
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55068 | 9.3 CRITICAL | free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisonin |
| CVE-2026-55784 | 7.5 HIGH | free5GC AUSF authentication contexts can be overwritten by concurrent requests for the sam |
No comments yet