First published: Thu Apr 20 2023(Updated: )
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONF SD-RAN ONOS | =2.5.1 | |
=2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29606 is considered to have a moderate severity due to its impact on network operability.
To address CVE-2022-29606, update ONOS to a version that properly handles large port numbers.
CVE-2022-29606 represents an improper handling issue that leads to misleading error states in the ONOS system.
CVE-2022-29606 affects ONOS version 2.5.1.
The potential impact of CVE-2022-29606 includes inconsistency between network intents and flow rules, which can lead to operational confusion.