img
img
img

News & Events

img

COORDINATED VULNERABILITY DISCLOSURE (CVD)

O-RAN ALLIANCE (O-RAN) recognizes the value of a Coordinated Vulnerability Disclosure (CVD) process in improving the security of its specification.
O-RAN provides a place for individuals or organizations to responsibly disclose a vulnerability that they have found in O-RAN specifications.
The O-RAN CVD Process is described on this page, from the moment of reporting to the resolution of the vulnerability, where O-RAN works with its members to develop fixes.
All reports are examined thoroughly, and the “Public Recognition” acknowledges those Finders who submitted validated vulnerabilities to O-RAN's CVD Process and opted-in to public recognition.
Disclosures to O-RAN's CVD Process must focus on O-RAN specifications. Reports of security vulnerabilities related to software implementations based on O-RAN specifications, including open-source software, should be reported using the process of the specific software organization and should be directed according to their processes. For the O-RAN Software Community (OSC) the vulnerability reporting process is described at the OSC website. Vulnerabilities related to specific implementations, including vendor implementations, should be disclosed directly to the relevant vendor organizations.

DEFINITIONS

CVD PROCESS

FINDER RESPONSIBILITIES

When submitting a vulnerability report, the Finder (individual or organization who has found a potential vulnerability) commits to:

O-RAN RESPONSIBILITIES

O-RAN will:

This submission form allows reporting vulnerabilities found in O-RAN specifications. By filing a vulnerability report you agree to O-RAN CVD Legal Notice.
Please provide as precise information as possible to allow proper vulnerability review and subsequent actions.
Mandatory fields are marked with *.

O-RAN ALLIANCE thanks to researchers and enthusiasts who discover vulnerabilities in O-RAN specifications and cooperate on addressing those.