{"id":"CVE-2025-5520","summary":"Open5GS AMF/MME emm_state_authentication assertion","details":"A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The manipulation leads to reachable assertion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 9f5d133657850e6167231527514ee1364d37a884. It is recommended to apply a patch to fix this issue. This is a different issue than CVE-2025-1893.","modified":"2026-08-12T15:16:43.926205Z","published":"2025-06-03T18:00:22.302Z","database_specific":{"cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5520.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.7.3"},{"last_affected":"2.7.3"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5520.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5520"},{"type":"ADVISORY","url":"https://vuldb.com/?id.310956"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.582269"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/3910"},{"type":"REPORT","url":"https://github.com/open5gs/open5gs/issues/3910#issuecomment-2926719317"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.310956"},{"type":"FIX","url":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/20362243/Problematic.handover.required.process.zip"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open5gs/open5gs","events":[{"introduced":"83e35bb2de7e67646fdba849580184422b10006a"},{"fixed":"9f5d133657850e6167231527514ee1364d37a884"}],"database_specific":{"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"},{"introduced":"2.7.1"},{"last_affected":"2.7.1"},{"introduced":"2.7.2"},{"last_affected":"2.7.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.7.0","2.7.1","2.7.2","v2.7.5","v2.7.2","v2.7.1","v2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5520.json","vanir_signatures_modified":"2026-08-12T15:16:43Z","vanir_signatures":[{"digest":{"length":8423,"function_hash":"83500632070580911998797047966065524410"},"id":"CVE-2025-5520-0ef524c2","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/amf/gmm-sm.c","function":"gmm_state_security_mode"},"deprecated":false},{"deprecated":false,"digest":{"length":7169,"function_hash":"160781599133266726046446224547111322076"},"id":"CVE-2025-5520-3a05cf93","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/amf/gmm-sm.c","function":"gmm_state_exception"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/mme/emm-sm.c","function":"emm_state_authentication"},"deprecated":false,"digest":{"function_hash":"22859958192396035505212974093563823443","length":4124},"id":"CVE-2025-5520-6869893c"},{"target":{"file":"src/amf/gmm-sm.c"},"deprecated":false,"digest":{"line_hashes":["162612948853236519870417624286336986397","279800737103072097352342639440643898857","224344108714082424795084970797513107060","92174190948770943019300478285797406489","11496801759268304833503557185898646113","279800737103072097352342639440643898857","63600953943289955141616430274593087484","256210522018344380583522769866622864221","8531826659309212253945361217639555917","279800737103072097352342639440643898857","63600953943289955141616430274593087484","256210522018344380583522769866622864221","88933678767554333444634080757504132882","279800737103072097352342639440643898857","63600953943289955141616430274593087484","98279082891080693496667047401417186958","218423668681304689602073986062147818177","279800737103072097352342639440643898857","63600953943289955141616430274593087484","98279082891080693496667047401417186958","218423668681304689602073986062147818177","287361486533403811949021440182620113055","329928212348722115459337753229020731516","221167672963450854736231568572233024945","171710928360583683359703307818570784637"],"threshold":0.9},"id":"CVE-2025-5520-7cf36230","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884"},{"source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/mme/emm-sm.c","function":"emm_state_exception"},"deprecated":false,"digest":{"function_hash":"7840338246266733304109947859179352179","length":2198},"id":"CVE-2025-5520-8258339c","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2025-5520-888aab85","signature_type":"Line","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/mme/emm-sm.c"},"deprecated":false,"digest":{"line_hashes":["181587525657022427075386250389554607630","214597673683049392675310664109267682895","44783538911283254919575295468980251765","17076408781526451615758545393702765642","181587525657022427075386250389554607630","252775408427670992673771619141331972551","258020227633328548922632536403702770528","133599961499748681934399517810130714389","181587525657022427075386250389554607630","193216346956972609628193931368582367486","210300223049496830621915461069147382003","14486022831773130212852169467389047262","181587525657022427075386250389554607630","53677434448106881679034576068327455465","22640183906031040781591380454654267857","135300274118787480034969130986824843604"],"threshold":0.9}},{"id":"CVE-2025-5520-ad2585fe","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/amf/gmm-sm.c","function":"common_register_state"},"deprecated":false,"digest":{"function_hash":"116882255355674317971163153045468861679","length":9739}},{"target":{"file":"src/mme/emm-sm.c","function":"emm_state_security_mode"},"deprecated":false,"digest":{"function_hash":"72387096183728905946385029289657893898","length":5578},"id":"CVE-2025-5520-b03c51d3","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884"},{"id":"CVE-2025-5520-d911ed6c","signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/amf/gmm-sm.c","function":"gmm_state_initial_context_setup"},"deprecated":false,"digest":{"function_hash":"58969063080390576501044478447730453268","length":8629}},{"signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"file":"src/amf/gmm-sm.c","function":"gmm_state_authentication"},"deprecated":false,"digest":{"function_hash":"126460456160147151523067791108123358265","length":8606},"id":"CVE-2025-5520-f9f3436d","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/open5gs/open5gs/commit/9f5d133657850e6167231527514ee1364d37a884","target":{"function":"emm_state_initial_context_setup","file":"src/mme/emm-sm.c"},"deprecated":false,"digest":{"function_hash":"59366305747887547644834116805621754724","length":5436},"id":"CVE-2025-5520-fc955644"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}