Metrics
Affected Vendors & Products
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Diameter S6a Interface. Performing a manipulation of the argument os.len results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.7.2 is able to mitigate this issue. The patch is named e89aa79efe629ae90f59dcdf8847c117d9a7da86. It is suggested to upgrade the affected component. | |
| Title | Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow | |
| First Time appeared |
Open5gs
Open5gs open5gs |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open5gs
Open5gs open5gs |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-12T16:58:14.188Z
Reserved: 2026-08-09T17:45:47.671Z
Link: CVE-2024-14042
Updated: 2026-08-12T15:51:58.621Z
Status : Deferred
Published: 2026-08-11T20:17:22.067
Modified: 2026-08-12T20:59:21.023
Link: CVE-2024-14042
No data.
OpenCVE Enrichment
Updated: 2026-08-12T20:15:03Z