An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (PGW-C), using the IP address of a legitimate UE in the PDN Address Allocation (PAA) field
| Software | From | Fixed in |
|---|---|---|
| open5gs / open5gs | - | 2.7.2.x |