VYPR

Onos

by Onosproject

Source repositories

CVEs (29)

  • CVE-2018-12691MedJul 5, 2018
    risk 0.44cvss 6.8epss 0.01

    Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection.

  • CVE-2022-24109MedApr 20, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent with a different key, and then remove the duplicate one. This will remove the flow rules of the intent, even though the intent still exists in…

  • CVE-2021-38364MedApr 20, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote attacker can install or remove a new intent, and consequently modify or delete the existing flow rules related to other intents.

  • CVE-2017-13763HigAug 30, 2017
    risk 0.42cvss 7.5epss 0.01

    ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.

  • CVE-2023-30093MedMay 4, 2023
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.

  • CVE-2017-13762MedAug 30, 2017
    risk 0.40cvss 6.1epss 0.01

    ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.

  • CVE-2017-1000078MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.01

    Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration

  • CVE-2022-29944MedApr 20, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of paths installed by intents. An existing intents does not redirect to a new path, even if a new intent that shares the path with higher priority is installed.

  • CVE-2022-29609MedApr 20, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the INSTALLING state, indicating that its flow rules are installing. Improper handling of such an intent is misleading to a network operator.

Page 2 of 2