CVE-2025-15687: Denial of Service in Open5GS
A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.
AI Analysis
Technical Summary
This vulnerability in Open5GS up to version 2.7.6 involves the smf_gx_cca_cb function within the SMF Diameter Gx Credit-Control-Answer Handler component. An attacker can remotely manipulate this function to cause a denial of service condition. The vulnerability has a CVSS 4.0 base score of 5.3, indicating medium severity. Public exploit code is available. The issue is fixed in Open5GS version 2.7.7, with the patch identified by commit f23d7a5e959acd8f37b925dc29b85f26b7d391cb.
Potential Impact
Successful exploitation results in denial of service, disrupting the affected Open5GS service component. The attack can be launched remotely without authentication or user interaction, potentially impacting availability of the SMF Diameter Gx Credit-Control-Answer Handler functionality.
Mitigation Recommendations
Upgrading Open5GS to version 2.7.7 or later is recommended to remediate this vulnerability. The patch commit f23d7a5e959acd8f37b925dc29b85f26b7d391cb addresses the issue. No other mitigations or temporary fixes are indicated.
CVE-2025-15687: Denial of Service in Open5GS
Description
A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.
CVSS v4.0
Score 5.3medium
Affected software
Open5GS
pkg:github/open5gs/open5gscpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Open5GS up to version 2.7.6 involves the smf_gx_cca_cb function within the SMF Diameter Gx Credit-Control-Answer Handler component. An attacker can remotely manipulate this function to cause a denial of service condition. The vulnerability has a CVSS 4.0 base score of 5.3, indicating medium severity. Public exploit code is available. The issue is fixed in Open5GS version 2.7.7, with the patch identified by commit f23d7a5e959acd8f37b925dc29b85f26b7d391cb.
Potential Impact
Successful exploitation results in denial of service, disrupting the affected Open5GS service component. The attack can be launched remotely without authentication or user interaction, potentially impacting availability of the SMF Diameter Gx Credit-Control-Answer Handler functionality.
Mitigation Recommendations
Upgrading Open5GS to version 2.7.7 or later is recommended to remediate this vulnerability. The patch commit f23d7a5e959acd8f37b925dc29b85f26b7d391cb addresses the issue. No other mitigations or temporary fixes are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-09T17:50:46.986Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7beb7cbf8831d539e77dd8
Added to database: 08/12/2026, 03:41:48 UTC
Last enriched: 08/12/2026, 04:00:45 UTC
Last updated: 09/26/2026, 01:47:37 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.