A nil-pointer dereference in free5GC's Policy Control Function (PCF) allows unauthenticated remote attackers to trigger a panic via a crafted POST request to the SM Policy Control endpoint. The vulnerability exists in versions prior to 4.2.2, where the HandleCreateSmPolicyRequest handler fails to properly handle 404 responses from downstream UDR lookups. When the OpenAPI consumer wrapper returns an error [truncated]
free5GC is an open-source implementation of the 5G core network. Prior to version 4.2.2, the Network Exposure Function (NEF) component mounts the 3gpp-pfd-management API without enforcing inbound OAuth2/bearer-token authorization. A network attacker with reachability to the NEF on the Service-Based Interface (SBI) can create, read, and delete PFD-management transaction state using a forged or arbitrary be [truncated]
free5GC UDM (Unified Data Management) component prior to version 4.2.2 contains an input validation vulnerability in the nudm-sdm (Subscriber Data Management) service. Six GET handlers fail to properly validate the supi path parameter, allowing unauthenticated attackers to inject control characters into the SUPI (Subscription Permanent Identifier) parameter. This injection causes UDM to forward malformed [truncated]
free5GC prior to version 4.2.2 contains a missing authentication vulnerability in the PCF (Policy Control Function) Npcf_SMPolicyControl service. The smPolicyGroup route group is registered without the RouterAuthorizationCheck middleware, allowing unauthenticated network requests to reach SM policy business logic. Affected endpoints include /npcf-smpolicycontrol/v1/sm-policies and related sub-resources. T [truncated]
A vulnerability in free5GC's Access and Mobility Management Function (AMF) prior to version 4.2.2 allows security context mismatches between the network and User Equipment (UE). The AMF fails to enforce concurrent security procedure rules from 3GPP TS 33.501 §6.9.5.1, specifically not checking for ongoing N2 handover procedures before initiating NAS Security Mode Command, and vice versa. This can result i [truncated]
A medium-severity vulnerability in free5GC's Access and Mobility Management Function (AMF) allows malicious gNodeBs to overwrite UE security capabilities, causing persistent handover denial-of-service. The AMF fails to validate UE Security Capabilities in NGAP PathSwitchRequest messages against locally stored values as required by 3GPP TS 33.501 §6.7.3.1. Arbitrary values propagate through PathSwitchReque [truncated]