PT-2023-28007 · O Ran Software Community · Ric-Plt-Lib-Rmr
Published
2023-09-01
·
Updated
2023-12-14
·
CVE-2023-41627
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
O-RAN Software Community ric-plt-lib-rmr version 4.9.0
Description
The issue is related to the lack of validation of the source of routing tables received by the device, potentially allowing attackers to send forged routing tables. This could lead to unauthorized modifications of the device's routing configuration.
Recommendations
For version 4.9.0, consider implementing source validation for routing tables to prevent forged updates until a patch is available. As a temporary workaround, restrict access to the routing table update mechanism to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ric-Plt-Lib-Rmr