CVE-2025-15555: Open5GS VoLTE Cx-Test hss-cx-path.c hss_ogs_diam_cx_mar_cb stack-based overflow
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hssogsdiamcxmarcb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGSKEYLEN results in stack-based buffer overflow. The attack may be launched remotely. The patch is identified as 54dda041211098730221d0ae20a2f9f9173e7a21. A patch should be applied to remediate this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15555?
CVE-2025-15555 is classified as a high-severity vulnerability due to the potential for a stack-based buffer overflow.
How do I fix CVE-2025-15555?
To fix CVE-2025-15555, update Open5GS to a version later than 2.7.6 where the vulnerability has been patched.
What software is affected by CVE-2025-15555?
CVE-2025-15555 affects Open5GS versions up to and including 2.7.6.
What is the impact of CVE-2025-15555?
The impact of CVE-2025-15555 includes the potential for arbitrary code execution due to a stack-based overflow.
In which component of Open5GS does CVE-2025-15555 occur?
CVE-2025-15555 occurs in the VoLTE Cx-Test component, specifically in the hss-cx-path.c file.