CVE-2026-30080

Source
https://cve.org/CVERecord?id=CVE-2026-30080
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-30080.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-30080
Published
2026-04-08T00:00:00Z
Modified
2026-07-16T03:48:24.389563355Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only security capability IA0, OpenAirInterface accepts and proceeds. This downgrade security context can lead to the possibility of replay attack.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30080.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf

Affected ranges

Type
GIT
Repo
https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf
Events
Introduced
5ad2873c649cb3da2702fb8c0748a77d79c51bf5
Last affected
5ad2873c649cb3da2702fb8c0748a77d79c51bf5
Database specific
{
    "cpe": "cpe:2.3:a:openairinterface:oai-cn5g-amf:2.2.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "2.2.0"
        },
        {
            "last_affected": "2.2.0"
        }
    ]
}

Affected versions

2.*
2.2.0
v2.*
v2.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-30080.json"