rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3

CVE-2026-93308

CVE-2026-93308 affects the VES Collector component of O-RAN-SC SMO OAM 2025-06-10. A remote attacker can manipulate an unknown functionality

Overview

CVE-2026-93308 affects the VES Collector component of O-RAN-SC SMO OAM 2025-06-10. A remote attacker can manipulate an unknown functionality to trigger resource allocation, potentially exhausting system resources. The vulnerability is publicly known but no patch has been released yet.

Description

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through a bug report but has not responded yet.

Impact

The flaw can lead to Denial of Service by exhausting memory or CPU resources, compromising Availability. It may also indirectly affect Confidentiality if resource exhaustion forces the system to fall back to insecure defaults. Network operators running O-RAN SMO OAM should consider this a moderate risk to service continuity.

Remediation

['Apply any vendor‑issued patch or update as soon as it becomes available.', 'If no patch is available, isolate the VES Collector service behind a firewall and restrict inbound traffic to trusted IP ranges.', 'Implement rate‑limiting or connection throttling on the VES Collector API endpoints.', 'Monitor system metrics for abnormal resource usage and set alerts for high memory or CPU consumption.']

Risk context

The CVSS v3 score is 4.3 and v4 is 5.3, indicating a medium severity vulnerability. With no EPSS data, the urgency is moderate; defenders should monitor vendor communications and apply mitigations promptly.

Affected products

  • O-RAN-SC SMO OAM 2025-06-10
  • VES Collector

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
5.3
EPSS

O-RAN SMO VES resource-allocation remote medium DoS

← All CVEs