CVE-2023-4884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
03/10/2023
Last modified:
05/10/2023

Description

An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* 2.4.10 (including)