Impact
A vulnerability in the VES Collector component of O‑RAN‑SC SMO OAM allows an attacker to manipulate the component via remote requests, causing it to allocate additional resources without restraint. This uncontrolled allocation can lead to resource exhaustion, degrading the availability of the service and potentially affecting other components that share infrastructure. The weakness is characterized by CWE‑400 (Uncontrolled Resource Consumption) and CWE‑770 (Reallocation from Allocated Resources).
Affected Systems
O‑RAN‑SC SMO OAM, version 2025‑06‑10. The vulnerability affects the VES Collector functionality within this product and is not limited to other components. Knowledge of affected versions is limited to the specified release, and no other affected versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact, while the EPSS score of less than 1% reflects a very low probability of exploitation at the moment. The vulnerability has not been added to the CISA KEV catalog, and no official patch or workaround is available. Although the attack vector is remote, an attacker can trigger the resource allocation using publicly available exploits. Monitoring is advisable, and applying a future vendor update should be prioritized.
OpenCVE Enrichment