rootpwn

medium · CVSS v3 5.3

CVE-2026-93310

CVE-2026-93310 is a medium‑severity vulnerability in the O‑RAN‑SC SMO OAM 2025‑06‑10 VES Collector component. It allows a remote attacker to

Overview

CVE-2026-93310 is a medium‑severity vulnerability in the O‑RAN‑SC SMO OAM 2025‑06‑10 VES Collector component. It allows a remote attacker to manipulate resource allocation, potentially exhausting system resources or causing denial of service. The flaw is publicly known and the vendor has not yet released a fix.

Description

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through a bug report but has not responded yet.

Impact

The vulnerability can lead to a compromise of the confidentiality, integrity, and availability of the O‑RAN network management stack. Resource exhaustion may degrade service for all connected base stations and control plane components, impacting operators and end‑users. Defenders should treat it as a potential denial‑of‑service vector that could be leveraged in larger attack campaigns.

Remediation

1. Apply any vendor‑issued patch or update for the VES Collector as soon as it becomes available. 2. If a patch is not yet released, isolate the VES Collector from untrusted networks and enforce strict firewall rules. 3. Enable logging and monitoring for abnormal resource allocation patterns and set alerts for sudden spikes. 4. Conduct a thorough review of the O‑RAN SMO configuration to ensure that only authenticated, authorized management traffic is allowed. 5. Consider implementing rate limiting or quota controls on VES Collector endpoints to mitigate resource exhaustion.

Risk context

The CVSS v3 score of 5.3 indicates a medium risk level. With no EPSS data, the urgency is driven by the public availability of the exploit and the lack of vendor response. Operators should prioritize monitoring and containment until a patch is released.

Affected products

  • O‑RAN‑SC SMO OAM 2025‑06‑10
  • VES Collector
  • O‑RAN SMO
  • O‑RAN OAM
  • O‑RAN VES

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
EPSS

resource-allocation remote-exploitation O-RAN SMO VES-Collector medium denial-of-service

← All CVEs