Onos
Vendor:
First CVE: Jul 17, 2017 · Active for 9 years
13
Total CVEs
More Total CVEs than 91% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Onos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
May 4, 2023
1,179 days ago
CVE Severity & Scoring
Onos13 CVEs
31%
38%
31%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13624CRITICAL In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command. | Jul 17, 2019 | 9.8 | 29 | NO | NO |
CVE-2017-1000081CRITICAL Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution. | Jul 17, 2017 | 9.8 | 29 | NO | NO |
CVE-2018-1000616CRITICAL ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConf | Jul 9, 2018 | 9.8 | 28 | NO | NO |
CVE-2018-1000614CRITICAL ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/N | Jul 9, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-13763HIGH ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited. | Aug 30, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-1000079HIGH Linux foundation ONOS 1.9.0 is vulnerable to a DoS. | Jul 17, 2017 | 7.5 | 23 | NO | NO |
CVE-2018-1000615HIGH ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely c | Jul 9, 2018 | 7.5 | 22 | NO | NO |
CVE-2017-1000080HIGH Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets. | Jul 17, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-13762MEDIUM ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS. | Aug 30, 2017 | 6.1 | 21 | NO | NO |
CVE-2023-30093MEDIUM A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted | May 4, 2023 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Onos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.0 | 6 | 7.4 | 1.4% | 0 | 0 |
| 1.8.0 | 6 | 7.4 | 1.4% | 0 | 0 |
| 1.15.0 | 1 | 9.8 | 1.9% | 0 | 0 |
| 1.10.0 | 2 | 6.8 | 1.1% | 0 | 0 |