Description
A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Uncontrolled Memory Allocation
Action: Patch ASAP
AI Analysis

Impact

A vulnerability exists in the VES Collector component of O-RAN-SC SMO OAM that allows an attacker to supply a specially crafted argument "additionalFields.padding" to trigger uncontrolled memory allocation. The flaw maps to missing resource bounds checking (CWE‑400) and memory allocation errors (CWE‑789), enabling a remote attacker to potentially exhaust system memory and render the service unavailable. The impact is a denial of service rather than arbitrary code execution, as the description does not indicate control over code flow or system privileges.

Affected Systems

The affected product is the SMO OAM suite from O‑RAN‑SC, specifically the VES Collector component released on 2025‑06‑10. No additional vendor or patch version information is available beyond the general SMO OAM designation.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the medium severity range, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, indicating it has not been observed as a high‑profile exploited vulnerability. Exfiltration can be launched remotely by sending a crafted request to the VES Collector; no local privilege or user interaction is required, which increases the attack surface. While the overall risk is moderate, operational continuity could be affected if the memory exhaustion occurs during peak traffic periods.

Generated by OpenCVE AI on September 19, 2026 at 08:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available vendor patch for SMO OAM 2025‑06‑10 that corrects the uncontrolled memory allocation.
  • Restrict network access to the VES Collector component to trusted hosts or networks to reduce the attack surface.
  • Monitor system memory usage and log entries for anomalous patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Title O-RAN-SC SMO OAM VES Collector memory allocation
First Time appeared O-ran-sc
O-ran-sc smo Oam
Weaknesses CWE-400
CWE-789
CPEs cpe:2.3:a:o-ran-sc:smo_oam:*:*:*:*:*:*:*:*
Vendors & Products O-ran-sc
O-ran-sc smo Oam
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

O-ran-sc Smo Oam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-23T17:53:54.780Z

Reserved: 2026-09-17T17:05:34.780Z

Link: CVE-2026-93307

cve-icon Vulnrichment

Updated: 2026-09-23T17:53:28.247Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:04.413

Modified: 2026-09-23T18:17:11.307

Link: CVE-2026-93307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:15:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-789

    Memory Allocation with Excessive Size Value