Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mosaic5g
Mosaic5g flexric |
|
| Vendors & Products |
Mosaic5g
Mosaic5g flexric |
Mon, 01 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Crash via Unimplemented E2AP Message Assertions | |
| Weaknesses | CWE-703 CWE-770 |
Mon, 01 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Crash via Unimplemented E2AP Message Assertions | |
| Weaknesses | CWE-703 CWE-770 |
Mon, 01 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-617 | |
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port 36421) via SIGABRT. The message passes whitelist validation but triggers an unconditional assertion in the handler. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-01T18:47:36.413Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37227
Updated: 2026-06-01T18:47:14.175Z
Status : Deferred
Published: 2026-06-01T17:16:58.993
Modified: 2026-06-01T21:16:42.667
Link: CVE-2026-37227
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:55:26Z