Junglewise Threat Intelligence

CVE-2026-93310: O-RAN-SC SMO OAM VES Collector resource exhaustion

CVE-2026-93310 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Technologies: O-RAN-SC SMO OAM. Vendors: O-RAN-SC.

Executive brief

O-RAN-SC SMO OAM is a network management component for Open RAN infrastructure. The VES (Virtual Event Streaming) Collector within it suffers from a resource exhaustion vulnerability that allows remote attackers to consume excessive memory or CPU through crafted event messages, potentially disrupting network management operations and degrading service availability.

Technical details

The vulnerability is a denial-of-service (CWE-770) issue in the VES Collector component of O-RAN-SC SMO OAM. The root cause involves improper resource management when processing heartbeat and event messages, allowing attackers to send specially crafted VES events that trigger unbounded resource allocation. The attack is network-reachable and requires no authentication; an attacker can send HTTP requests to the collector's event listener endpoint (default port 8080) with malicious payloads. Proof-of-concept exploit code demonstrates a "sleeper attack" pattern using multiple concurrent threads to flood the collector with events designed to exhaust system resources. Patches or updates have not been provided by the project team as of the advisory date.

Affected products

  • O-RAN-SC SMO OAM 2025-06-10

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: advisory: CVE-2026-93310 advisory published

References

Related threats