Vulnerability Description
A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component PFCP. The manipulation results in improper initialization. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been made public and could be used. The patch is identified as 773117aa5472af26fc9f80e608d3386504c3bdb7. It is best practice to apply a patch to resolve this issue.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open5Gs | Open5Gs | <= 2.7.5 |
Related Weaknesses (CWE)
References
- https://github.com/open5gs/open5gs/
- https://github.com/open5gs/open5gs/commit/773117aa5472af26fc9f80e608d3386504c3bdPatch
- https://github.com/open5gs/open5gs/issues/4182ExploitIssue TrackingVendor Advisory
- https://github.com/open5gs/open5gs/issues/4182#issue-3670797098ExploitIssue TrackingVendor Advisory
- https://github.com/open5gs/open5gs/issues/4182#issuecomment-3616081878Issue Tracking
- https://vuldb.com/?ctiid.337591Permissions RequiredVDB Entry
- https://vuldb.com/?id.337591Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.716841Third Party AdvisoryVDB Entry
- https://github.com/open5gs/open5gs/issues/4182ExploitIssue TrackingVendor Advisory
- https://github.com/open5gs/open5gs/issues/4182#issue-3670797098ExploitIssue TrackingVendor Advisory
- https://github.com/open5gs/open5gs/issues/4182#issuecomment-3616081878Issue Tracking
FAQ
What is CVE-2025-14955?
CVE-2025-14955 is a vulnerability with a CVSS score of 3.7 (LOW). A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component PFCP. The manipulation re...
How severe is CVE-2025-14955?
CVE-2025-14955 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14955?
Check the references section above for vendor advisories and patch information. Affected products include: Open5Gs Open5Gs.