Vulnerability Description
Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| O-Ran-Sc | Ric Message Router | 4.9.0 |
Related Weaknesses (CWE)
References
- https://jira.o-ran-sc.org/browse/RIC-991ExploitIssue TrackingVendor Advisory
- https://www.trendmicro.com/en_us/research/23/l/the-current-state-of-open-ran-sec
- https://jira.o-ran-sc.org/browse/RIC-991ExploitIssue TrackingVendor Advisory
- https://www.trendmicro.com/en_us/research/23/l/the-current-state-of-open-ran-sec
FAQ
What is CVE-2023-40997?
CVE-2023-40997 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.
How severe is CVE-2023-40997?
CVE-2023-40997 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-40997?
Check the references section above for vendor advisories and patch information. Affected products include: O-Ran-Sc Ric Message Router.