Description
A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via uncontrolled resource allocation
Action: Assess Patch
AI Analysis

Impact

A flaw in the VES Collector component of O-RAN‑SC SMO OAM allows an attacker to manipulate unknown functionality to allocate resources without bounds. The vulnerability is a classic case of uncontrolled resource consumption (CWE‑400) and unbounded allocation (CWE‑770). When triggered it can exhaust system resources, degrade performance, and ultimately prevent the service from responding to legitimate requests. The description indicates that the attack can be launched remotely and public exploits are available.

Affected Systems

The affected system is the O‑RAN‑SC SMO OAM product, specifically the VES Collector component in the 2025-06-10 release. No additional versions or variants are enumerated in the data.

Risk and Exploitability

The CVSS score of 5.3 classifies this as a moderate severity vulnerability, while the EPSS of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the target remotely, but a public exploit has been disclosed, and the project has not yet released a fix. The risk remains moderate because of the potential service disruption, but the likelihood is low.

Generated by OpenCVE AI on September 19, 2026 at 07:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest O‑RAN‑SC SMO OAM release once a patch is available
  • Restrict access to the VES Collector by applying firewall or network segmentation rules so that only trusted management traffic can reach it
  • Configure operating‑system resource limits or use container‑level controls to cap CPU and memory usage for the VES Collector process

Generated by OpenCVE AI on September 19, 2026 at 07:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Title O-RAN-SC SMO OAM VES Collector allocation of resources
First Time appeared O-ran-sc
O-ran-sc smo Oam
Weaknesses CWE-400
CWE-770
CPEs cpe:2.3:a:o-ran-sc:smo_oam:*:*:*:*:*:*:*:*
Vendors & Products O-ran-sc
O-ran-sc smo Oam
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

O-ran-sc Smo Oam
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T02:00:51.165Z

Reserved: 2026-09-17T17:05:48.359Z

Link: CVE-2026-93309

cve-icon Vulnrichment

Updated: 2026-09-22T02:00:45.809Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T00:17:49.010

Modified: 2026-09-22T03:16:57.930

Link: CVE-2026-93309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:00:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling