CVE-2025-66720
7.5free5gc · pcf
A null pointer dereference vulnerability exists in free5gc pcf 1.4.0 within the HandleDeletePoliciesPolAssoId function, potentially causing a service crash.
Executive summary
A null pointer dereference vulnerability in free5gc pcf 1.4.0 poses a high risk of service disruption due to potential denial of service conditions.
Vulnerability
The vulnerability is a null pointer dereference occurring in the internal/sbi/processor/ampolicy.go file within the HandleDeletePoliciesPolAssoId function. This flaw allows an unauthenticated remote attacker to trigger a crash of the affected component.
Business impact
Successful exploitation of this vulnerability results in a denial of service, which can lead to significant system downtime for critical 5G core network functions. Given the CVSS score of 7.5, the vulnerability represents a high-severity risk to availability, as it can be triggered remotely by an unauthenticated attacker without requiring user interaction.
Remediation
Immediate Action: Review the provided vendor references on GitHub to track the status of the fix and apply the corresponding security update as soon as the vendor releases a patched version.
Proactive Monitoring: Monitor system logs for repeated service failures or unexpected restarts of the pcf component, which may indicate attempted exploitation.
Compensating Controls: Implement network segmentation and access control lists to restrict traffic to the affected Service Based Interface (SBI) to only authorized network elements.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing free5gc pcf version 1.4.0 should prioritize monitoring for service instability and prepare to apply patches immediately upon vendor release. Given the availability of a proof-of-concept and the critical nature of core network infrastructure, proactive defense and strict network access controls are essential to mitigate the risk of denial of service.