VendorsONOS Projectonosall versions
Vulnerabilities

ONOS Project ONOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2019-13624
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
Published 2019-07-17 · Modified
10.0EPSS 0.019
CVE-2017-1000081
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
Published 2017-07-13 · Modified
9.8EPSS 0.030
CVE-2018-1000614
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/NetconfAlarmTranslator.java that can result in An adversary can remotely launch advanced XXE attacks on ONOS controller without authentication.. This attack appear to be exploitable via crafted protocol message.
Published 2018-07-09 · Modified
9.8EPSS 0.016
CVE-2018-1000616
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity.
Published 2018-07-09 · Modified
9.8EPSS 0.014
CVE-2015-7516
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with ether_type Jumbo Frame (0x8870).
Published 2017-08-24 · Modified
7.8EPSS 0.037
CVE-2017-1000079
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
Published 2017-07-13 · Modified
7.5EPSS 0.013
CVE-2018-1000615
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB service ONOS controller via a normal switch.. This attack appear to be exploitable via the attacker should be able to control or forge a switch in the network..
Published 2018-07-09 · Modified
7.5EPSS 0.012
CVE-2017-13763
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.
Published 2017-08-30 · Modified
7.5EPSS 0.011
CVE-2017-1000080
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
Published 2017-07-13 · Modified
7.5EPSS 0.010
CVE-2018-12691
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection.
Published 2018-07-05 · Modified
6.8EPSS 0.007
CVE-2017-13762
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
Published 2017-08-30 · Modified
6.1EPSS 0.012
CVE-2017-1000078
Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration
Published 2017-07-13 · Modified
6.1EPSS 0.007
CVE-2023-30093
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.
Published 2023-05-04 · Modified
6.1EPSS 0.005