CVE-2025-65563
7.5omec-project · UPF (upf-epc/pfcpiface)
An unauthenticated denial-of-service vulnerability in the omec-project UPF allows remote attackers to crash the service by sending malformed PFCP Association Setup Request messages.
Executive summary
The omec-project UPF is vulnerable to a remote denial-of-service attack that allows unauthenticated actors to crash the process and disrupt user-plane traffic.
Vulnerability
This is a null pointer dereference flaw triggered when the UPF receives a PFCP Association Setup Request missing the mandatory NodeID Information Element. The vulnerability is remotely exploitable by unauthenticated attackers targeting the N4/PFCP endpoint.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting its high impact on service availability. Successful exploitation results in the immediate termination of the UPF process, leading to service disruption for connected users and potential operational downtime for network infrastructure.
Remediation
Immediate Action: Monitor the official omec-project repository for the release of a patched version and apply the update immediately upon availability.
Proactive Monitoring: Review N4/PFCP interface logs for repeated Association Setup Request messages that precede process crashes or service instability.
Compensating Controls: Implement firewall rules to restrict access to the N4/PFCP endpoint to trusted internal components only, effectively limiting the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for significant service disruption, network administrators should prioritize restricting network access to the UPF's N4/PFCP interface. While a definitive patch is pending, applying network-level segmentation to prevent unauthorized PFCP traffic is the most effective temporary mitigation. Ensure teams are prepared to deploy the vendor-supplied fix as soon as it is released.