CVE-2025-41067: Reachable Assertion vulnerability in Open5GS
Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41067?
CVE-2025-41067 is classified as a high severity vulnerability due to its potential to cause denial of service in the affected Open5GS software.
How do I fix CVE-2025-41067?
To fix CVE-2025-41067, users should upgrade Open5GS to the latest version beyond 2.7.5 to mitigate the vulnerability.
What impact does CVE-2025-41067 have on Open5GS?
CVE-2025-41067 allows attackers to crash the NRF process, leading to disruption of the discovery service in Open5GS.
Who is affected by CVE-2025-41067?
CVE-2025-41067 affects any user of Open5GS versions up to and including 2.7.5 that has connectivity to the NRF.
What type of vulnerability is CVE-2025-41067?
CVE-2025-41067 is a Reachable Assertion vulnerability in the Open5GS software.