Cyber Resilience

CVE-2023-41627

O-Ran-Sc Ric Message Router 4.9.0

Published
01 September 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.012 67th percentile
Risk Priority 60 floored blend · peak EPSS

Summary

CVE-2023-41627 is a high-severity an unspecified weakness vulnerability in O-Ran-Sc Ric Message Router. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 33% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-40997Same product: O-Ran-Sc Ric Message Router
CVE-2023-40998Same product: O-Ran-Sc Ric Message Router
CVE-2024-34047Same vendor: O-Ran-Sc
CVE-2023-42358Same vendor: O-Ran-Sc
CVE-2023-41628Same vendor: O-Ran-Sc
CVE-2024-34048Same vendor: O-Ran-Sc

Affected Assets

o-ran-sc
ric message router
4.9.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References