S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-38870 Scanner

CVE-2022-38870 scanner - Information Disclosure vulnerability in Free5gc

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-38870
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Free5gc v3.2.1 is vulnerable to Information disclosure.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Free5gc is an open-source 5G core network system that is used to enable network slicing, isolate 5G services from each other, and provide security and privacy to the end-users. It is designed to work efficiently with various radio access technologies to ensure seamless connectivity and improved quality of service to the users. Its primary objective is to aid developers, researchers, and vendors to experiment, test, and prototype the latest 3GPP standards.

CVE-2022-38870 is a vulnerability that was recently detected in Free5gc v3.2.1. It is an information disclosure vulnerability that can be triggered by an attacker who has access to the network traffic. The vulnerability is caused by an error in handling the PDU Session Resource Modification Request (PDU SMR) message, which could lead to the disclosure of sensitive information, including user credentials and other sensitive data. 

When exploited, the vulnerability can have severe consequences for the users and the system as a whole. The attacker can easily intercept network traffic, decrypt sensitive information, and launch further attacks. This can lead to data loss, abuse, and manipulation, which can jeopardize the privacy and security of the end-users. 

In conclusion, it is essential to maintain the security and privacy of our digital assets and networks. The s4e.io platform provides pro features that enable users to easily and quickly learn about vulnerabilities in their digital assets. With its intelligent scanning and reporting capabilities, it can help detect and remediate vulnerabilities in real-time, ensuring that our digital assets remain secure and protected. Stay ahead of cyber threats and protect your digital assets with s4e.io.

 

REFERENCES

Solution Advice

The following precautions can be taken to prevent the exploitation of CVE-2022-38870:

  • Update the Free5gc software to the latest version, which should include a patch for the vulnerability.
  • Implement strong access control measures to restrict access to the network traffic and user data.
  • Use secure communication protocols such as Transport Layer Security (TLS) to encrypt network traffic.
  • Monitor network traffic for any suspicious activity and detect and respond to any unusual behavior in real-time.
  • Educate users on good cybersecurity practices, such as using strong and unique passwords, avoiding public Wi-Fi networks, and being cautious while browsing the internet.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.