一、 漏洞 CVE-2025-1893 基础信息
漏洞标题
Open5GS UDM 用户数据管理 gmm-sm.c gmm_state_authentication 拒绝服务漏洞
来源:AIGC 神龙大模型
漏洞描述信息
在Open5GS 2.7.2及之前版本中发现了一个漏洞。该漏洞已被确认为存在问题。此漏洞影响组件UDM用户数据管理中的文件src/amf/gmm-sm.c中的gmm_state_authentication功能。此操作会导致拒绝服务。攻击可以通过远程方式发起。漏洞利用细节已公开,可能会被利用。修复此漏洞的补丁名为e31e9965f00d9c744a7f728497cb4f3e97744ee8。建议应用补丁以解决此问题。
来源:AIGC 神龙大模型
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
来源:AIGC 神龙大模型
漏洞类别
不恰当的资源关闭或释放
来源:AIGC 神龙大模型
漏洞标题
Open5GS AMF gmm-sm.c gmm_state_authentication denial of service
来源:美国国家漏洞数据库 NVD
漏洞描述信息
A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is the function gmm_state_authentication of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vulnerability allows a single UE to crash the AMF, resulting in the complete loss of mobility and session management services and causing a network-wide outage. All registered UEs will lose connectivity, and new registrations will be blocked until the AMF is restarted, leading to a high availability impact. The exploit has been disclosed to the public and may be used. The patch is named e31e9965f00d9c744a7f728497cb4f3e97744ee8. It is recommended to apply a patch to fix this issue.
来源:美国国家漏洞数据库 NVD
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
来源:美国国家漏洞数据库 NVD
漏洞类别
不恰当的资源关闭或释放
来源:美国国家漏洞数据库 NVD
二、漏洞 CVE-2025-1893 的公开POC
# POC 描述 源链接 神龙链接
三、漏洞 CVE-2025-1893 的情报信息
  • 标题: [Bug]: During the UE's handover between two gNBs, an abnormal state transition in the AMF's handling of UDM subscriber data management may result in an AMF crash. · Issue #3707 · open5gs/open5gs -- 🔗来源链接

    标签: issue-tracking

  • 标题: [Bug]: During the UE's handover between two gNBs, an abnormal state transition in the AMF's handling of UDM subscriber data management may result in an AMF crash. · Issue #3707 · open5gs/open5gs -- 🔗来源链接

    标签: issue-tracking

  • 标题: [Bug]: During the UE's handover between two gNBs, an abnormal state transition in the AMF's handling of UDM subscriber data management may result in an AMF crash. · Issue #3707 · open5gs/open5gs -- 🔗来源链接

    标签: exploit issue-tracking

  • 标题: [AMF] Fix AMF crash during UE handover by handling unexpected SBI res… · open5gs/open5gs@e31e996 · GitHub -- 🔗来源链接

    标签: patch

  • 标题: Login required -- 🔗来源链接

    标签: signature permissions-required

  • 标题: Submit #505952: Open5GS v2.7.2 Denial of Service -- 🔗来源链接

    标签: third-party-advisory

  • 标题: CVE-2025-1893 Open5GS AMF gmm-sm.c gmm_state_authentication denial of service (Issue 3707) -- 🔗来源链接

    标签: vdb-entry technical-description

  • https://nvd.nist.gov/vuln/detail/CVE-2025-1893