Impact
The FlexRIC v2.0.0 near‑RT RIC contains reachable assert(0) calls in stub handlers for E2AP message types that are whitelisted but unimplemented, such as E2nodeConfigurationUpdate. When an attacker sends a decodable message of one of these types, the handler executes the unconditional assertion, causing the process to abort with SIGABRT and the service to terminate. This results in a denial of service for all tenants using the RIC. The presence of these assertions reflects weaknesses classified as CWE‑617.
Affected Systems
The affected component is the near‑RT RIC module of FlexRIC version 2.0.0. No other vendor or product variations are listed in the available data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact. EPSS information is not available, and the vulnerability is not included in the CISA KEV catalog. The attack vector is remote and unauthenticated, requiring only network access to port 36421 on the RIC. Because the trigger is deterministic and the condition simply involves receiving a specific E2AP message type, the likelihood of exploitation is high if the service is exposed to untrusted networks.
OpenCVE Enrichment