free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no Authorization header at all, or with a forged bearer token (e.g. Authorization: Bearer not-a-real-token). This includes creating AnyUeInd=true subscriptions intended to affect group / any-UE traffic steering. The route group is also reachable even when the running config's ServiceList does not declare it, so operators who think they disabled the service via config are still exposed. This vulnerability is fixed in 4.2.2.
The NEF (Network Exposure Function) component in free5GC mounts a routing group for the 3gpp-traffic-influence API without Authorization header verification — both requests without any token and requests with arbitrarily fabricated bearer tokens are accepted. Moreover, the vulnerable routing group remains available even if the operator disabled the service in the configuration (ServiceList), making administrative disabling ineffective. An attacker can thereby create, read, modify, and delete traffic-influence subscriptions, including subscriptions with the AnyUeInd=true flag affecting all traffic of a group or any UE.
An attacker can seize control over traffic control policies in the 5G network — by creating, modifying, or deleting traffic-influence subscriptions, they can disrupt or redirect traffic of all network users (AnyUeInd=true), leading to loss of integrity and availability of network services. Unauthorized reading of subscription data is also possible.
Update free5GC to version 4.2.2 or later, in which the fix has been implemented. Details are available in the official security advisory from the vendor and pull request #23 in the free5gc/nef repository.
free5GC (open-source implementation of 5G core network) in versions prior to 4.2.2 — NEF (Network Exposure Function) component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:HFree5gc
APPFree5Gc< 4.2.2
Related vulnerabilities
free5GC NEF: brak autoryzacji OAuth2 na trasach nnef-pfdmanagement
free5GC SMF: brak autoryzacji OAuth2 na endpointach UPI — pełny dostęp bez uwierzytelnienia
Brak autoryzacji OAuth2 w grupie tras OAM w free5GC NEF (5G core)
Brak autoryzacji OAuth2 w NEF API sieci 5G (free5GC)
CSRF w Free5GC umożliwia nieautoryzowane zarządzanie użytkownikami