First published: Thu Apr 20 2023(Updated: )
An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent with a different key, and then remove the duplicate one. This will remove the flow rules of the intent, even though the intent still exists in the controller.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opennetworking Onos | =2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.