Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Onos
(Onosproject)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 13 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-05-04 | CVE-2023-30093 | A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard. | Onos | 6.1 | ||
2017-07-17 | CVE-2017-1000081 | Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution. | Onos | 9.8 | ||
2017-07-17 | CVE-2017-1000080 | Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets. | Onos | 7.5 | ||
2017-07-17 | CVE-2017-1000079 | Linux foundation ONOS 1.9.0 is vulnerable to a DoS. | Onos | 7.5 | ||
2017-07-17 | CVE-2017-1000078 | Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration | Onos | 6.1 | ||
2018-07-09 | CVE-2018-1000615 | ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB service ONOS controller via a normal switch.. This attack appear to be exploitable via the attacker should be able to control or forge a switch in the network.. | Onos | 7.5 | ||
2017-08-30 | CVE-2017-13763 | ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited. | Onos | 7.5 | ||
2019-07-17 | CVE-2019-13624 | In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command. | Onos | 9.8 | ||
2018-07-05 | CVE-2018-12691 | Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection. | Onos | 6.8 | ||
2018-07-09 | CVE-2018-1000616 | ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity. | Onos | 9.8 |