Description
A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Assess Impact
AI Analysis

Impact

A vulnerability in the VES Collector component of O‑RAN‑SC SMO OAM allows an attacker to manipulate the component via remote requests, causing it to allocate additional resources without restraint. This uncontrolled allocation can lead to resource exhaustion, degrading the availability of the service and potentially affecting other components that share infrastructure. The weakness is characterized by CWE‑400 (Uncontrolled Resource Consumption) and CWE‑770 (Reallocation from Allocated Resources).

Affected Systems

O‑RAN‑SC SMO OAM, version 2025‑06‑10. The vulnerability affects the VES Collector functionality within this product and is not limited to other components. Knowledge of affected versions is limited to the specified release, and no other affected versions are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact, while the EPSS score of less than 1% reflects a very low probability of exploitation at the moment. The vulnerability has not been added to the CISA KEV catalog, and no official patch or workaround is available. Although the attack vector is remote, an attacker can trigger the resource allocation using publicly available exploits. Monitoring is advisable, and applying a future vendor update should be prioritized.

Generated by OpenCVE AI on September 19, 2026 at 08:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Contact O‑RAN‑SC to obtain a patch or revised release that fixes the VES Collector resource allocation bug.
  • Restrict network exposure of the VES Collector service by limiting inbound connections to trusted networks or using a firewall to block external access.
  • Configure system resource limits or monitoring alerts so that unexpectedly high resource usage by the VES Collector is detected and mitigated before it impacts overall availability.

Generated by OpenCVE AI on September 19, 2026 at 08:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through a bug report but has not responded yet.
Title O-RAN-SC SMO OAM VES Collector allocation of resources
First Time appeared O-ran-sc
O-ran-sc smo Oam
Weaknesses CWE-400
CWE-770
CPEs cpe:2.3:a:o-ran-sc:smo_oam:*:*:*:*:*:*:*:*
Vendors & Products O-ran-sc
O-ran-sc smo Oam
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

O-ran-sc Smo Oam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T12:59:16.466Z

Reserved: 2026-09-17T17:05:44.260Z

Link: CVE-2026-93308

cve-icon Vulnrichment

Updated: 2026-09-18T12:59:09.782Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T00:17:48.830

Modified: 2026-09-18T13:23:37.403

Link: CVE-2026-93308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:00:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling