First published: Thu Apr 20 2023(Updated: )
An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an invalid flow rule, causing a network loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONF SD-RAN ONOS | =2.5.1 | |
=2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29608 has a moderate severity rating due to the potential to create network loops.
To fix CVE-2022-29608, upgrade ONOS to a version later than 2.5.1 where the vulnerability is addressed.
CVE-2022-29608 can lead to network loops, which significantly degrade network performance and cause interruptions.
Yes, CVE-2022-29608 can be exploited remotely if an attacker can manipulate intents containing specific port configurations.
CVE-2022-29608 specifically affects ONOS version 2.5.1.