O-RAN-SC Vulnerability Management & Coordinated Disclosure

O-RAN-SC Vulnerability Management & Coordinated Disclosure

Overview

The O-RAN Software Community (O-RAN-SC) takes security seriously and follows a Coordinated Vulnerability Disclosure (CVD) process to manage and resolve security vulnerabilities responsibly. This framework aligns with established practices from LF Networking (LFN) projects (like FD.io , ONAP, and OpenDaylight) and the broader O-RAN ALLIANCE CVD policies.

Recently collated and fixed CVEs can be found HERE

Scope & Where to Report

To ensure your report is handled by the correct team, please review the scope below:

  • O-RAN Software Community (OSC): This process covers security vulnerabilities related specifically to software implementations developed by O-RAN-SC. (Report these here)

  • O-RAN Specifications: If the vulnerability lies within the underlying O-RAN architecture or specifications rather than the software implementation, it must be reported directly to the O-RAN ALLIANCE via their CVD Submission Form.

  • Vendor Implementations: Vulnerabilities in specific proprietary vendor products or specific implementations should be disclosed directly to the respective vendor's security team.

How to Report a Vulnerability (Private Workflow)

To protect the community and users, do not publicly disclose potential security vulnerabilities in public forums, mailing lists, IRC, or standard public bug trackers.

  1. Submit Privately: Send your report privately to the O-RAN-SC Security Team at security@o-ran-sc.org.

  2. Keep it Confidential: Treat all information as confidential until a coordinated disclosure date is mutually agreed upon.

Reporting Email Template Please use the following template when emailing security@o-ran-sc.org to ensure the team has the necessary information to reproduce and assess the flaw:

Subject: Vulnerability Report: [Insert brief title of the vulnerability]

  • Reporter Name / Nickname:

  • Reporter Organization (Optional):

  • Affected O-RAN-SC Project / Component: (Include version numbers if known)

  • Vulnerability Details: (Provide a detailed description of the vulnerability)

  • Steps to Reproduce: (Provide step-by-step circumstances to reproduce the issue, or attach a Proof-of-Concept)

  • Potential Exploits: (Describe what an attacker could achieve using this vulnerability)

  • Estimated Severity: (Critical, High, Medium, or Low)

  • Is this currently being exploited? (Yes/No/Unknown)

Vulnerability Management Workflow

  1. Reception & Triage: The Security Team will acknowledge receipt of the report (typically within 7 days) and triage the report with Subject Matter Experts to determine its validity.

  2. Embargo & Patch Development: If confirmed as a security flaw, the issue enters an "Embargo" period. The community will work on a fix privately, aiming to have a resolution plan within 90 days of the initial report.

  3. Risk Assessment: The vulnerability will be evaluated and scored based on its impact into one of four categories: Critical, Important, Moderate, or Low.

  4. CVE Assignment: The security team will request a Common Vulnerabilities and Exposures (CVE) identifier from a CNA for traceability.

  5. Coordinated Disclosure: Once the patch is peer-reviewed and tested, a coordinated disclosure date is agreed upon. On this date, the bug is made public, the patch is merged, and a security advisory is published to the community.

o-ran-sc.png

Finder Responsibilities

Finders are expected to act in good faith and commit to the following:

  • Maintain strict confidentiality until the CVD process is terminated and the fix is published.

  • Do not exploit the vulnerability beyond what is minimally necessary to demonstrate the issue.

  • Do not leverage the vulnerability for financial gain. Taking into consideration that O-RAN is a standards development organization, the O-RAN ALLIANCE and O-RAN-SC do not provide financial compensation for vulnerability reports