Onos

Vendor:

First CVE: Jul 17, 2017 · Active for 9 years

13
Total CVEs
More Total CVEs than 91% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Onos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
May 4, 2023
1,179 days ago

CVE Severity & Scoring

Onos13 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
Jul 17, 20199.829NONO
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
Jul 17, 20179.829NONO
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConf
Jul 9, 20189.828NONO
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/N
Jul 9, 20189.828NONO
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.
Aug 30, 20177.523NONO
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
Jul 17, 20177.523NONO
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely c
Jul 9, 20187.522NONO
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
Jul 17, 20177.522NONO
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
Aug 30, 20176.121NONO
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted
May 4, 20236.120NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Onos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.067.41.4%00
1.8.067.41.4%00
1.15.019.81.9%00
1.10.026.81.1%00