CVE-2025-15687
Deferred Deferred - Pending Action

Denial of Service in Open5GS SMF Diameter Gx Handler

Vulnerability report for CVE-2025-15687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: VulDB

Description

A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
open5gs open5gs to 2.7.7 (exc)
open5gs open5gs 2.7.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service flaw in Open5GS up to version 2.7.6. It occurs in the SMF Diameter Gx Credit-Control-Answer Handler function when processing delayed responses. The issue arises when the SMF receives a late Gx CCA response for a session that has already been deleted, causing an assertion failure and crashing the SMF component.

Detection Guidance

Monitor Open5GS SMF logs for assertion failures or crashes related to delayed Gx Credit-Control-Answer (CCA) responses. Check for logs containing 'smf_gx_cca_cb: Assertion 'sess' failed' or similar errors indicating session handling issues.

Impact Analysis

The vulnerability can lead to service disruption as the SMF crashes when processing delayed responses. This may cause network outages or degraded performance in 4G EPC deployments using Open5GS, especially during rapid UE attach and detach scenarios. The exploit is remotely launchable and has been publicly disclosed.

Compliance Impact

This vulnerability causes denial of service by crashing the SMF component when processing delayed Gx Credit-Control-Answer responses. Such disruptions could impact availability of critical network functions, potentially violating compliance requirements for service continuity in standards like GDPR (data processing availability) and HIPAA (healthcare system reliability).

Mitigation Strategies

Upgrade Open5GS to version 2.7.7 or later to address the vulnerability. Apply the patch identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb to enhance exception handling in Diameter callback functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart