📦 Onos

by Opennetworking

🔍 What is Onos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-41591

CRITICAL CVSS 9.8 May 29, 2025

CVE-2023-41591 is an authentication bypass vulnerability in ONOS SDN controller that allows attackers to spoof IP/MAC addresses. This enables man-in-the-middle attacks on network communications betwee...

CVE-2025-29312

CRITICAL CVSS 9.1 Mar 24, 2025

This vulnerability in ONOS (Open Network Operating System) v2.7.0 allows attackers to trigger unexpected behavior in devices connected to legacy switches by manipulating link types from indirect to di...

CVE-2025-29310

CRITICAL CVSS 9.8 Mar 24, 2025

A critical vulnerability in ONOS v2.7.0 allows attackers to execute arbitrary commands or access network information by sending a specially crafted LLDP packet. This affects any system running the vul...

CVE-2022-29604

CRITICAL CVSS 9.8 Apr 20, 2023

This vulnerability in ONOS (Open Network Operating System) causes improper handling of case sensitivity in device IDs, leading to misleading CORRUPT state displays for intents with uppercase letters. ...

CVE-2022-29606

CRITICAL CVSS 9.8 Apr 20, 2023

A vulnerability in ONOS 2.5.1 allows network operators to create intents with large port numbers that cause system inconsistencies. When exploited, this leads to misleading CORRUPT state displays and ...

CVE-2022-29608

HIGH CVSS 7.5 Apr 20, 2023

This vulnerability in ONOS (Open Network Operating System) allows attackers to create network loops by crafting malicious intents with intermediate port specifications. This affects organizations usin...

CVE-2021-38363

HIGH CVSS 7.5 Apr 20, 2023

This vulnerability in ONOS (Open Network Operating System) allows memory exhaustion through orphaned intents that cannot be cleaned up. When an intent installation fails with an exception, it remains ...

CVE-2022-24035

HIGH CVSS 7.5 Apr 20, 2023

A vulnerability in ONOS 2.5.1's intent framework causes purge-requested intents to remain active but unresponsive to topology changes like link failures. This can lead to network management failures w...