PT-2025-7889 · O Ran · O-Ran Near Realtime Ric

Published

2025-02-25

·

Updated

2025-02-25

·

CVE-2024-34036

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions O-RAN Near Realtime RIC I-Release (affected versions not specified)
Description An issue was discovered that allows an attacker to disrupt the initial connection between a gNB and the Near RT-RIC. This can be achieved by sending a high volume of subscription requests via an xApp, potentially inundating the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Assertion Failure

Weakness Enumeration

Related Identifiers

CVE-2024-34036

Affected Products

O-Ran Near Realtime Ric