PT-2026-45430 · Undefined · Undefined
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FlexRIC version 2.0.0
Description
A remote unauthenticated attacker can cause the near-RT RIC to crash on port 36421. The issue occurs when an SCTP (Stream Control Transmission Protocol) association is closed before an
E2 SETUP REQUEST is sent. The system incorrectly assumes a mapping between the SCTP association and the E2 node always exists during the cleanup path and enforces this using an assert() function, leading to a crash if the mapping is missing. This can be triggered by completing an SCTP handshake and disconnecting immediately without sending any E2AP messages.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined