PT-2026-45456 · Undefined · Undefined
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FlexRIC version 2.0.0
Description
The near-RT RIC contains reachable
assert(0) calls within stub message handlers for E2AP message types that are whitelisted but not yet implemented. A remote unauthenticated attacker can cause the near-RT RIC process on port 36421 to crash via SIGABRT by sending a decodable E2AP PDU of an unimplemented type, such as E2nodeConfigurationUpdate. The message successfully passes whitelist validation but triggers an unconditional assertion in the handler.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined