top of page
perceptive_background_267k.jpg

FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a mapping between SCTP association and E2 …

Published:

31 May 2026 at 22:00:00

Alert date:

1 June 2026 at 18:04:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Critical Infrastructure

FlexRIC v2.0.0 contains a denial of service vulnerability where the near-RT RIC crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The application incorrectly assumes a mapping between SCTP association and E2 node always exists in the cleanup path and enforces this via assert(). A remote unauthenticated attacker can exploit this by completing an SCTP handshake on port 36421 and immediately disconnecting without sending any E2AP message, causing the near-RT RIC to crash. This vulnerability affects the 5G RAN Intelligent Controller component used in O-RAN networks.

Technical details

Mitigation steps:

Affected products:

FlexRIC

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page