CVE-2025-65561
7.5free5GC · free5GC
A vulnerability in the LocalNode.Sess function of free5GC 4.1.0 allows unauthenticated attackers to cause a denial of service via a crafted PFCP Session Modification Request.
Executive summary
A critical denial of service vulnerability in free5GC version 4.1.0 allows unauthenticated remote attackers to disrupt session management processes.
Vulnerability
This vulnerability resides in the LocalNode.Sess function, where improper handling of the Local SEID header within a PFCP Session Modification Request allows an unauthenticated attacker to trigger a crash or service disruption.
Business impact
The exploitation of this flaw leads to a denial of service, which can severely impact the availability of 5G core network functions. Given the CVSS score of 7.5, this high severity vulnerability poses a significant risk to network operations, potentially leading to widespread service outages and requiring immediate attention to maintain system uptime.
Remediation
Immediate Action: Consult the official free5GC repository and associated pull requests to identify and apply the necessary code fixes or configuration changes to address the LocalNode.Sess vulnerability.
Proactive Monitoring: Monitor system logs for repeated PFCP Session Modification Requests or unexpected crashes in the LocalNode component that may indicate exploitation attempts.
Compensating Controls: Implement network-level filtering to restrict access to the PFCP interface, ensuring only authorized network elements can communicate with the vulnerable service.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this denial of service vulnerability necessitates immediate review of the affected free5GC deployment. Administrators should prioritize applying the vendor-provided fixes or workarounds identified in the upstream pull request to prevent service disruption and ensure the continued stability of the network core.