Unrated severityOSV Advisory· Published Jul 9, 2018· Updated Sep 17, 2024
CVE-2018-1000616
CVE-2018-1000616
Description
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity.
Affected products
1- Range: 1.0.0, 1.1.0, 1.1.0-rc2, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- gms.cl0udz.com/Openconfig_xxe.pdfmitrex_refsource_MISC
- gerrit.onosproject.orgmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.