PT-2026-45512 · Git+1 · Flexric
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FlexRIC version 2.0.0
Description
An authorization bypass exists in the iApp xApp isolation mechanism. The function
eq xapp ric gen id() in src/ric/iApp/xapp ric id.c incorrectly compares m0->xapp id against itself instead of comparing it to m1->xapp id, which ignores the xApp identity dimension. Consequently, a malicious xApp connected to the iApp via port 36422 can delete subscriptions belonging to any other xApp by sending an E42 RIC SUBSCRIPTION DELETE REQUEST with a matching ric gen id. This flaw compromises multi-tenant isolation in deployments where multiple xApps share the same RIC.Recommendations
For version 2.0.0, update the
eq xapp ric gen id() function to correctly compare m0->xapp id with m1->xapp id to ensure proper xApp identity verification.Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flexric