CVE-2025-7485 – Open5GS Reachable Assertion Vulnerability

The following table lists the changes that have been made to the
CVE-2025-7485 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 12, 2025

    Action Type Old Value New Value
    Added Description A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial Message Handler. The manipulation leads to reachable assertion. The attack needs to be approached locally. The patch is named cfa44575020f3fb045fd971358442053c8684d3d. It is recommended to apply a patch to fix this issue.
    Added CVSS V4.0 AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
    Added CVSS V2 (AV:L/AC:L/Au:S/C:N/I:N/A:P)
    Added CWE CWE-617
    Added Reference https://github.com/open5gs/open5gs/commit/cfa44575020f3fb045fd971358442053c8684d3d
    Added Reference https://github.com/open5gs/open5gs/issues/3878#issuecomment-2853775136
    Added Reference https://github.com/open5gs/open5gs/issues/3878/
    Added Reference https://vuldb.com/?ctiid.316135
    Added Reference https://vuldb.com/?id.316135
    Added Reference https://vuldb.com/?submit.610601
Share the Post:

Related Posts