PT-2026-45430 · Undefined · Undefined

·

CVE-2026-37220

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FlexRIC version 2.0.0
Description A remote unauthenticated attacker can cause the near-RT RIC to crash on port 36421. The issue occurs when an SCTP (Stream Control Transmission Protocol) association is closed before an E2 SETUP REQUEST is sent. The system incorrectly assumes a mapping between the SCTP association and the E2 node always exists during the cleanup path and enforces this using an assert() function, leading to a crash if the mapping is missing. This can be triggered by completing an SCTP handshake and disconnecting immediately without sending any E2AP messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-37220

Affected Products

Undefined