Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Alto CVE-2026-55784 Multiple Vendors

Vulnerabilidad alta en free5GC 1.4.4 permite acceso no autorizado a contexto de autenticación

Vulnerabilidad · Publicado 28/08/2026 · Actualizado 29/08/2026

7.5
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

free5GC, implementación de código abierto del núcleo 5G, presenta una vulnerabilidad en el componente AUSF (Authentication Server Function) en versiones 1.4.4 y anteriores. El almacenamiento inseguro de estado de autenticación por suscriptor en una estructura global permite que atacantes accedan o manipulen credenciales de usuarios. Esta vulnerabilidad afecta directamente a operadores de telecomunicaciones y proveedores de infraestructura 5G en LATAM que ejecuten free5GC en entornos de producción.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by SUPI. Every request handled by internal/sbi/processor/ue_authentication.go creates an AusfUeContext, and AddAusfUeContextToPool executes ausfContext.UePool.Store(ausfUeContext.Supi, ausfUeContext), unconditionally replacing the active context for that SUPI. An attacker with access to the AUSF SBI/N12 interface can send concurrent POST /nausf-auth/v1/ue-authentications requests for the same target SUPI, causing all attempts to share one logical authentication context URL while K_aut, XRES, and EapID are repeatedly overwritten. A valid EAP-AKA' response for an earlier challenge is then checked against the latest context, causing AT_MAC verification to fail and denying authentication to the selected subscriber while the request flood continues. No fixed version is available as of this review.

Puntuación CVSS

Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Debilidades (CWE)

CWE-362

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Verificar inventario de sistemas con free5GC 1.4.4 o anterior
  • Aplicar parches disponibles del fabricante inmediatamente
  • Si no hay parches, implementar mitigaciones de red (restricción de acceso a componentes AUSF)
  • Revisar logs de autenticación para detectar accesos anómalos
  • Consultar NIST NVD para actualizaciones de vulnerabilidad (CVSS 7.5)
Esta alerta fue generada automáticamente a partir del NVD del NIST.
← Volver a todas las alertas