Impact
A flaw in the VES Collector component of O-RAN‑SC SMO OAM allows an attacker to manipulate unknown functionality to allocate resources without bounds. The vulnerability is a classic case of uncontrolled resource consumption (CWE‑400) and unbounded allocation (CWE‑770). When triggered it can exhaust system resources, degrade performance, and ultimately prevent the service from responding to legitimate requests. The description indicates that the attack can be launched remotely and public exploits are available.
Affected Systems
The affected system is the O‑RAN‑SC SMO OAM product, specifically the VES Collector component in the 2025-06-10 release. No additional versions or variants are enumerated in the data.
Risk and Exploitability
The CVSS score of 5.3 classifies this as a moderate severity vulnerability, while the EPSS of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the target remotely, but a public exploit has been disclosed, and the project has not yet released a fix. The risk remains moderate because of the potential service disruption, but the likelihood is low.
OpenCVE Enrichment