An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-open5gs | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-10-03 15:15
Updated : 2023-10-05 00:57
NVD link : CVE-2023-4884
Mitre link : CVE-2023-4884
CVE.ORG link : CVE-2023-4884
JSON object : View
Products Affected
open5gs
- open5gs
CWE
CWE-306
Missing Authentication for Critical Function