Vulnerability Description
O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| O-Ran-Sc | Ric Message Router | 4.9.0 |
References
- https://jira.o-ran-sc.org/browse/RIC-1001Vendor Advisory
- https://www.trendmicro.com/en_us/research/23/l/the-current-state-of-open-ran-sec
- https://jira.o-ran-sc.org/browse/RIC-1001Vendor Advisory
- https://www.trendmicro.com/en_us/research/23/l/the-current-state-of-open-ran-sec
FAQ
What is CVE-2023-41627?
CVE-2023-41627 is a vulnerability with a CVSS score of 7.5 (HIGH). O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.
How severe is CVE-2023-41627?
CVE-2023-41627 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41627?
Check the references section above for vendor advisories and patch information. Affected products include: O-Ran-Sc Ric Message Router.