CVE-2026-30080
7.5OpenAirInterface · OpenAirInterface v2
OpenAirInterface v2 is vulnerable to a security context downgrade, allowing unauthenticated attackers to bypass integrity protection and potentially facilitate replay attacks.
Executive summary
A security context downgrade vulnerability in OpenAirInterface v2 allows unauthenticated attackers to bypass integrity protection, creating a significant risk of replay attacks.
Vulnerability
The vulnerability exists because the software accepts a Security Mode Complete message without integrity protection when a user equipment sends an initial registration request using only security capability IA0. This flaw allows an unauthenticated remote attacker to downgrade the security context of the connection.
Business impact
The ability to downgrade security contexts poses a severe risk to network integrity and confidentiality. By bypassing mandatory integrity checks, an attacker could potentially execute replay attacks, leading to unauthorized command injection or session manipulation. With a CVSS score of 7.5, this high severity vulnerability warrants immediate attention to prevent potential service disruption or unauthorized data interception.
Remediation
Immediate Action: Monitor official OpenAirInterface security channels and the referenced GitLab issue for the release of a security patch or configuration hardening guidance.
Proactive Monitoring: Review access logs and signaling traffic for anomalous registration requests that utilize restricted security capabilities like IA0.
Compensating Controls: Implement strict network access control policies to isolate affected components and restrict traffic from untrusted sources while awaiting vendor-supplied updates.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for unauthorized network manipulation and the presence of a known proof-of-concept, organizations utilizing OpenAirInterface v2 must prioritize the implementation of defensive measures. Administrators should track the provided GitLab repository for updates and move to apply the necessary patches as soon as they become available to secure the signaling interface against downgrade attacks.