Mosaic5g

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    0
    Critical Level Threats
    15
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-37230

    FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() in Debug builds (SIGABRT) or NULL pointer dereference in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the near-RT RIC (port 36421) by sending a crafted RIC_INDICATION with an arbitrary ran_func_id value.

    Last Modified: Jun 03, 2026
    Published: Jun 01, 2026

    CVE-2026-37220

    SCTP Handshake Mismanagement Causes Remote Denial of Service in FlexRIC

    Last Modified: Jun 02, 2026
    Published: Jun 01, 2026

    CVE-2026-37221

    Unvalidated ric_id crash in FlexRIC v2.0.0

    Last Modified: Jun 02, 2026
    Published: Jun 01, 2026

    CVE-2026-37222

    FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can send a valid E2AP PDU containing an unexpected number of IEs (e.g., an E2setupRequest with extra optional fields) to crash the near-RT RIC (port 36421) or iApp (port 36422) via SIGABRT. The code asserts exact IE counts rather than validating against protocol-specified ranges.

    Last Modified: Jun 02, 2026
    Published: Jun 01, 2026

    CVE-2026-37226

    FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds (SIGSEGV). A remote unauthenticated attacker can crash the iApp process (port 36422) by sending a subscription request with an arbitrary global_e2_node_id.

    Last Modified: Jun 03, 2026
    Published: Jun 01, 2026
    Items Per Page
    Mosaic5g Vulnerabilities & Security CVEs | CVE-DB