Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mosaic5g
Mosaic5g flexric |
|
| Vendors & Products |
Mosaic5g
Mosaic5g flexric |
Tue, 02 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Denial of Service via E42_RIC_SUBSCRIPTION_REQUEST Validation Mismatch in FlexRIC |
Mon, 01 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Crash on Empty ricEventTriggerDefinition in FlexRIC | |
| Weaknesses | CWE-20 |
Mon, 01 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Crash on Empty ricEventTriggerDefinition in FlexRIC | |
| Weaknesses | CWE-20 |
Mon, 01 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-617 | |
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition field. The E42 layer decoder accepts this as valid, but the E2AP encoder asserts a non-empty constraint when forwarding the request. A remote unauthenticated attacker can crash the iApp process (port 36422) via SIGABRT by exploiting this cross-layer validation mismatch. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-01T18:48:24.429Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37225
Updated: 2026-06-01T18:48:18.543Z
Status : Deferred
Published: 2026-06-01T17:16:58.880
Modified: 2026-06-01T21:16:42.500
Link: CVE-2026-37225
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:55:27Z