Back to Database
Status published
Medium
CVE-2023-4884
Multiple vulnerabilities in Open5GS
Vulnerability Description
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4884
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Pablo Valle Alvear
More from Open5GS
View All →CVE-2023-4885
Multiple vulnerabilities in Open5GS
Medium
6.5
CVE-2023-4883
Multiple vulnerabilities in Open5GS
High
7.5
CVE-2023-4882
Multiple vulnerabilities in Open5GS
High
7.5
CVE-2023-23846
Due to insufficient length validation in the Open5GS GTP library...
Unknown
0
CVE-2022-39063
When Open5GS UPF receives a PFCP Session Establishment Request, it...
High
7.5
Affected Vendor
Open5GS
View all reports →Affected Software
Open5GS
Vulnerable Versions:
2.4.10 and prior
Timeline
Official Publish:
October 3rd, 2023
Last Modified:
September 19th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L