An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of an intent into an OpenFlow 1.0 switch that does not support IPv6. Improper handling of the difference in capabilities of the intent and switch is misleading to a network operator.
References
Link | Resource |
---|---|
https://wiki.onosproject.org/display/ONOS/Intent+Framework | Product |
https://www.usenix.org/system/files/sec23fall-prepub-285_kim-jiwon.pdf | Exploit Technical Description Third Party Advisory |
Configurations
History
04 May 2023, 15:35
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:opennetworking:onos:2.5.1:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-670 | |
References | (MISC) https://wiki.onosproject.org/display/ONOS/Intent+Framework - Product | |
References | (MISC) https://www.usenix.org/system/files/sec23fall-prepub-285_kim-jiwon.pdf - Exploit, Technical Description, Third Party Advisory |
20 Apr 2023, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-20 13:15
Updated : 2024-02-04 23:37
NVD link : CVE-2022-29605
Mitre link : CVE-2022-29605
CVE.ORG link : CVE-2022-29605
JSON object : View
Products Affected
opennetworking
- onos
CWE
CWE-670
Always-Incorrect Control Flow Implementation