CVE-2026-2524

medium

Description

A flaw has been found in Open5GS 2.7.6. The impacted element is the function mme_s11_handle_create_session_response of the component MME. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References

https://vuldb.com/?submit.738369

https://vuldb.com/?id.346112

https://vuldb.com/?ctiid.346112

https://github.com/open5gs/open5gs/issues/4284#issue-3808462406

https://github.com/open5gs/open5gs/issues/4284

https://github.com/open5gs/open5gs/

Details

Source: Mitre, NVD

Published: 2026-02-16

Updated: 2026-02-16

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium