Impact
A flaw in the VES Collector of O‑RAN‑SC SMO OAM allows an attacker to manipulate resource allocation, leading to uncontrolled memory or CPU usage. The vulnerability is classified as a moderate severity with a CVSS score of 6.9 and can be exploited remotely. The exploitation code is publicly available, which increases the potential for real-world attacks.
Affected Systems
The affected product is O‑RAN‑SC SMO OAM, specifically the VES Collector component of the 2025-06-10 release. No other versions or components are explicitly listed, and the version identifiers are not provided apart from the release date.
Risk and Exploitability
Because the vulnerability can be exploited remotely without authentication and the exploit is openly available, the risk is tangible even though the EPSS score is low (under 1%). The CVSS score of 6.9 reflects potential for significant denial of service or resource depletion. Since the issue is not listed in CISA’s KEV catalog, no elevated exposure is indicated, but the presence of a public exploit means the attack surface is ready for deployment.
OpenCVE Enrichment