Onosproject develops ONOS, a software-defined networking platform widely deployed in carrier and enterprise networks, with exposures that recur across its core controller and traffic-steering application. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate around web-interface input handling, XML processing, resource-management, and concurrency issues typical of large-scale distributed network control software. Live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onosproject over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13624CRITICAL In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command. | Jul 17, 2019 | 9.8 | 29 | NO | NO |
CVE-2017-1000081CRITICAL Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution. | Jul 17, 2017 | 9.8 | 29 | NO | NO |
CVE-2018-1000616CRITICAL ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConf | Jul 9, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-1000614CRITICAL ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/N | Jul 9, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-13763HIGH ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited. | Aug 30, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-1000079HIGH Linux foundation ONOS 1.9.0 is vulnerable to a DoS. | Jul 17, 2017 | 7.5 | 23 | NO | NO |
CVE-2024-34049HIGH Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in reader.go. | Apr 30, 2024 | 7.5 | 22 | NO | NO |
CVE-2018-1000615HIGH ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely c | Jul 9, 2018 | 7.5 | 22 | NO | NO |
CVE-2017-1000080HIGH Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets. | Jul 17, 2017 | 7.5 | 22 | NO | NO |
CVE-2024-34050HIGH Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64(b[0])" in reader.go. | Apr 30, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onosproject.
Media articles that mention a CVE ID that affects a product developed by Onosproject — matched by CVE ID, not by vendor name.