img
img
img

News & Events

img

COORDINATED VULNERABILITY DISCLOSURE (CVD)

O-RAN ALLIANCE (O-RAN) recognizes the value of a Coordinated Vulnerability Disclosure (CVD) process in improving the security of its specification.
O-RAN provides a place for individuals or organizations to responsibly disclose a vulnerability that they have found in O-RAN specifications.
The O-RAN CVD Process is described on this page, from the moment of reporting to the resolution of the vulnerability, where O-RAN works with its members to develop fixes.
All reports are examined thoroughly, and the “Public Recognition” acknowledges those Finders who submitted validated vulnerabilities to O-RAN's CVD Process and opted-in to public recognition.
Disclosures to O-RAN's CVD Process must focus on O-RAN specifications. Reports of security vulnerabilities related to software implementations based on O-RAN specifications, including open-source software, should be reported using the process of the specific software organization and should be directed according to their processes. For the O-RAN Software Community (O-RAN SC) the vulnerability reporting process is described at the O-RAN SC website. Vulnerabilities related to specific implementations, including vendor implementations, should be disclosed directly to the relevant vendor organizations.

DEFINITIONS

CVD PROCESS

FINDER RESPONSIBILITIES

When submitting a vulnerability report, the Finder (individual or organization who has found a potential vulnerability) commits to:

O-RAN RESPONSIBILITIES

O-RAN will:

This submission form allows reporting vulnerabilities found in O-RAN specifications. By filing a vulnerability report you agree to O-RAN CVD Legal Notice.
Please provide as precise information as possible to allow proper vulnerability review and subsequent actions.
Mandatory fields are marked with *.

O-RAN ALLIANCE thanks to researchers and enthusiasts who discover vulnerabilities in O-RAN specifications and cooperate on addressing those.