PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15687 Open5GS CVE debrief

A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb.

Vendor
Open5GS
Product
Open5GS
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-29
Advisory published
2026-08-12
Advisory updated
2026-09-29

Who should care

Defenders responsible for Open5GS installations should assess exposure and prioritize upgrading to version 2.7.7 if vulnerable. They should also review source-provided details for accurate affected scope and severity assessment, and monitor for remote attacks. This includes verifying the security of their Open5GS deployments, understanding the potential operational impacts, and taking appropriate measures to mitigate the vulnerability.

Why it matters

CVE-2025-15687 is a denial of service vulnerability in Open5GS up to 2.7.6. Defenders should verify exposure, prioritize upgrading to version 2.7.7, and monitor for remote attacks.

  • Verify exposure of Open5GS installations
  • Upgrade to version 2.7.7 if vulnerable
  • Monitor for remote attacks and potential denial of service

Technical summary

The function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler in Open5GS up to 2.7.6 is vulnerable to denial of service. The attack can be launched remotely. Defenders should prioritize verifying exposure and upgrading to version 2.7.7 if vulnerable, while reviewing source-provided technical details for accurate impact assessment and potential mitigations. This vulnerability impacts Open5GS installations, specifically the SMF component, and its exploitation could lead to service disruption.

Defensive priority

Defenders should prioritize verifying exposure of Open5GS installations and upgrading to version 2.7.7 if vulnerable.

Recommended defensive actions

  • Verify Open5GS installations for exposure
  • Upgrade to version 2.7.7 if vulnerable
  • Monitor for remote attacks
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Plan vendor-supported updates through normal change control

Evidence notes

The CVE record and source metadata indicate a denial of service vulnerability in Open5GS up to 2.7.6. The attack can be launched remotely. Upgrading to version 2.7.7 is recommended. Defenders should verify exposure and review source-provided details for accurate affected scope and severity assessment. Evidence limits suggest remote attack feasibility but require defensive validation.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15687 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15687

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15687 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15687

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.