Impact
A vulnerability exists in the VES Collector component of O-RAN-SC SMO OAM that allows an attacker to supply a specially crafted argument "additionalFields.padding" to trigger uncontrolled memory allocation. The flaw maps to missing resource bounds checking (CWE‑400) and memory allocation errors (CWE‑789), enabling a remote attacker to potentially exhaust system memory and render the service unavailable. The impact is a denial of service rather than arbitrary code execution, as the description does not indicate control over code flow or system privileges.
Affected Systems
The affected product is the SMO OAM suite from O‑RAN‑SC, specifically the VES Collector component released on 2025‑06‑10. No additional vendor or patch version information is available beyond the general SMO OAM designation.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, indicating it has not been observed as a high‑profile exploited vulnerability. Exfiltration can be launched remotely by sending a crafted request to the VES Collector; no local privilege or user interaction is required, which increases the attack surface. While the overall risk is moderate, operational continuity could be affected if the memory exhaustion occurs during peak traffic periods.
OpenCVE Enrichment