CVE-2025-65565

7.5

omec-project · UPF (pfcpiface component)

A denial of service vulnerability in the omec-project UPF pfcpiface component allows remote attackers to crash the service via a malformed PFCP Session Establishment Request.

Executive summary

The omec-project UPF pfcpiface component is vulnerable to a denial of service attack that can result in the termination of the user-plane process.

Vulnerability

This is a null pointer dereference vulnerability triggered by the absence of a mandatory F-SEID Information Element during PFCP session establishment. An unauthenticated attacker can send crafted requests to the N4/PFCP endpoint to trigger a process panic and service disruption.

Business impact

The exploitation of this flaw leads to a loss of availability for critical user-plane services, which can severely impact network operations and connectivity for downstream users. Given the CVSS score of 7.5, this high severity vulnerability represents a significant risk to service continuity for organizations relying on this infrastructure.

Remediation

Immediate Action: Monitor the vendor repository for the release of a patch that properly validates the presence of the F-SEID Information Element in PFCP requests.

Proactive Monitoring: Review N4/PFCP interface traffic for anomalous Session Establishment Requests and monitor system logs for signs of repetitive process panics or service restarts.

Compensating Controls: Implement network access control lists (ACLs) to restrict access to the N4/PFCP endpoint to only trusted and authorized network elements.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the omec-project UPF should treat this vulnerability with high priority, as the lack of authentication requirements makes the service susceptible to remote disruption. We recommend restricting network access to the pfcpiface component immediately and applying the official vendor patch as soon as it becomes available to restore service stability.

Sources