CVE-2026-30079
EUVD-2026-1964207.04.2026, 15:17
In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeComplete message is sent after InitialUERegistration, a registration reject is received followed by a registration accept! This leads the UE to be registered without proper authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openairinterface | oai-cn5g-amf | 2.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration