O-RAN-SC Vulnerability Management & Coordinated Disclosure
Overview
The O-RAN Software Community (O-RAN-SC) takes security seriously and follows a Coordinated Vulnerability Disclosure (CVD) process to manage and resolve security vulnerabilities responsibly. This framework aligns with established practices from LF Networking (LFN) projects (like FD.io , ONAP, and OpenDaylight) and the broader O-RAN ALLIANCE CVD policies.
Recently collated and fixed CVEs can be found HERE
Scope & Where to Report
To ensure your report is handled by the correct team, please review the scope below:
O-RAN Software Community (OSC): This process covers security vulnerabilities related specifically to software implementations developed by O-RAN-SC. (Report these here)
O-RAN Specifications: If the vulnerability lies within the underlying O-RAN architecture or specifications rather than the software implementation, it must be reported directly to the O-RAN ALLIANCE via their CVD Submission Form.
Vendor Implementations: Vulnerabilities in specific proprietary vendor products or specific implementations should be disclosed directly to the respective vendor's security team.
How to Report a Vulnerability (Private Workflow)
To protect the community and users, do not publicly disclose potential security vulnerabilities in public forums, mailing lists, IRC, or standard public bug trackers.
Submit Privately: Send your report privately to the O-RAN-SC Security Team at security@o-ran-sc.org.
Keep it Confidential: Treat all information as confidential until a coordinated disclosure date is mutually agreed upon.
Reporting Email Template Please use the following template when emailing security@o-ran-sc.org to ensure the team has the necessary information to reproduce and assess the flaw:
Subject: Vulnerability Report: [Insert brief title of the vulnerability]
Reporter Name / Nickname:
Reporter Organization (Optional):
Affected O-RAN-SC Project / Component: (Include version numbers if known)
Vulnerability Details: (Provide a detailed description of the vulnerability)
Steps to Reproduce: (Provide step-by-step circumstances to reproduce the issue, or attach a Proof-of-Concept)
Potential Exploits: (Describe what an attacker could achieve using this vulnerability)
Estimated Severity: (Critical, High, Medium, or Low)
Is this currently being exploited? (Yes/No/Unknown)
Vulnerability Management Workflow
Reception & Triage: The Security Team will acknowledge receipt of the report (typically within 7 days) and triage the report with Subject Matter Experts to determine its validity.
Embargo & Patch Development: If confirmed as a security flaw, the issue enters an "Embargo" period. The community will work on a fix privately, aiming to have a resolution plan within 90 days of the initial report.
Risk Assessment: The vulnerability will be evaluated and scored based on its impact into one of four categories: Critical, Important, Moderate, or Low.
CVE Assignment: The security team will request a Common Vulnerabilities and Exposures (CVE) identifier from a CNA for traceability.
Coordinated Disclosure: Once the patch is peer-reviewed and tested, a coordinated disclosure date is agreed upon. On this date, the bug is made public, the patch is merged, and a security advisory is published to the community.
Finder Responsibilities
Finders are expected to act in good faith and commit to the following:
Maintain strict confidentiality until the CVD process is terminated and the fix is published.
Do not exploit the vulnerability beyond what is minimally necessary to demonstrate the issue.
Do not leverage the vulnerability for financial gain. Taking into consideration that O-RAN is a standards development organization, the O-RAN ALLIANCE and O-RAN-SC do not provide financial compensation for vulnerability reports