Aller au contenu

Fiche vulnérabilité

CVE-2021-41794 : faille élevée open5gs open5gs (CVSS 7.5)

Description

ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character is interpreted as a length value to be used in a memcpy call. The destination buffer is only 100 bytes long on the stack. Then, 'i' gets interpreted as 105 bytes to copy from the source buffer to the destination buffer.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
7 oct. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • open5gs open5gs

Références

Rechercher une autre vulnérabilité dans la base CVE