Known Vulnerabilities for Flexric by Mosaic5g
Listed below are 7 of the newest known vulnerabilities associated with "Flexric" by "Mosaic5g".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-37235 json | FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The va... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37234 json | FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnec... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37233 json | FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37232 json | An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calc... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37231 json | FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,530+ ... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37230 json | FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its r... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37229 json | FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthen... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37228 json | FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed ... | Not Provided | 2026-06-01 | 2026-06-02 |
| CVE-2026-37227 json | FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message typ... | Not Provided | 2026-06-01 | 2026-06-01 |
| CVE-2026-37226 json | FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup ... | Not Provided | 2026-06-01 | 2026-06-02 |