Home/Product/opennetworking onos
Product

opennetworking onos

33 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-53423
all versions
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.
5.6MEDIUM
CVE-2023-41591
all versions
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-
9.8CRITICAL
CVE-2025-29312
all versions
An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing
9.1CRITICAL
CVE-2025-29311
all versions
Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attac
7.5HIGH
CVE-2025-29310
all versions
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vu
9.8CRITICAL
CVE-2024-48809
all versions
An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of
7.5HIGH
CVE-2023-30093
>= 1.9.0 and <= 2.7.0
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to ex
6.1MEDIUM
CVE-2022-29944
all versions
An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of paths installed by intents. An existing intents does no
5.3MEDIUM
CVE-2022-29609
all versions
An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the INSTALLING state, indicating that
5.3MEDIUM
CVE-2022-29608
all versions
An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an invalid flow ru
7.5HIGH
CVE-2022-29607
all versions
An issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source and destination shows the INSTAL
7.5HIGH
CVE-2022-29606
all versions
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a networ
9.8CRITICAL
CVE-2022-29605
all versions
An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of an intent into an OpenFlow 1.0 swi
7.5HIGH
CVE-2022-29604
all versions
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is mislead
9.8CRITICAL
CVE-2022-24109
all versions
An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate i
6.5MEDIUM
CVE-2022-24035
all versions
An issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topol
7.5HIGH
CVE-2021-38364
all versions
An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote attacker can
6.5MEDIUM
CVE-2021-38363
all versions
An issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendi
7.5HIGH
CVE-2023-24279
>= 1.9.0 and <= 2.7.0
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to ex
6.1MEDIUM
CVE-2019-11189
<= 2.0.0
Authentication Bypass by Spoofing in org.onosproject.acl (access control) and org.onosproject.mobility (host mobility) in ONOS v2.
7.5HIGH
CVE-2019-13624
all versions
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within s
9.8CRITICAL
CVE-2018-1999020
<= 1.13.2
Open Networking Foundation (ONF) ONOS version 1.13.2 and earlier version contains a Directory Traversal vulnerability in core/comm
5.5MEDIUM
CVE-2018-1000616
<= 1.13.1
ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\m
9.8CRITICAL
CVE-2018-1000615
<= 1.13.1
ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in O
7.5HIGH
CVE-2018-1000614
<= 1.13.1
ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/
9.8CRITICAL
CVE-2018-12691
<= 1.13.0
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and
6.8MEDIUM
CVE-2017-13763
all versions
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.
7.5HIGH
CVE-2017-13762
all versions
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
6.1MEDIUM
CVE-2015-7516
<= 1.4.0
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switc
7.5HIGH
CVE-2017-1000081
all versions
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
9.8CRITICAL
CVE-2017-1000080
all versions
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
7.5HIGH
CVE-2017-1000079
all versions
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
7.5HIGH
CVE-2017-1000078
all versions
Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration
6.1MEDIUM
threatengine.sh