First published: Thu Apr 20 2023(Updated: )
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of case sensitivity causes inconsistency between intent and flow rules in the network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONF SD-RAN ONOS | =2.5.1 | |
=2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29604 has a medium severity level due to its potential to mislead network operators.
To fix CVE-2022-29604, ensure consistent case handling in device IDs within ONOS 2.5.1.
CVE-2022-29604 specifically affects ONOS version 2.5.1.
CVE-2022-29604 can lead to confusion for network operators by displaying a CORRUPT state due to case sensitivity issues.
A possible workaround for CVE-2022-29604 is to standardize device IDs to lowercase to avoid the misleading CORRUPT state.