First published: Thu Apr 20 2023(Updated: )
An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote attacker can install or remove a new intent, and consequently modify or delete the existing flow rules related to other intents.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONF SD-RAN ONOS | =2.5.1 | |
=2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38364 is classified as a moderate severity vulnerability due to its potential impact on the integrity of flow rules in ONOS.
To fix CVE-2021-38364, update your ONOS software to a version later than 2.5.1 that addresses the vulnerability.
The risks associated with CVE-2021-38364 include unauthorized modification or deletion of flow rules, which may disrupt network operations.
Users of ONOS version 2.5.1 are affected by CVE-2021-38364 and should take action to mitigate the vulnerability.
Yes, CVE-2021-38364 can be exploited remotely, allowing attackers to alter flow rules through malicious intent installations.