CVE-2024-34035
CVSS 3.1 Score 5.7 of 10 (medium)
Details
Summary
CVE-2024-34035 is a newly discovered vulnerability affecting the O-RAN Near Realtime RIC H-Release. This issue allows an adversary to cause the e2mgr to crash by flooding the system with an excessive number of E2 Subscription Requests originating from an xApp. Successful exploitation of this vulnerability could lead to system instability and potential denial-of-service attacks. The O-RAN Alliance is urged to release a patch to address this issue and mitigate the risk to impacted networks. Until a patch is available, organizations should implement rate-limiting mechanisms to prevent excessive traffic from xApps and protect against potential denial-of-service attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.