Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opennetworking

First CVE: May 24, 2018Active for: 8 yearsTotal CVEs: 63
40.2
VTI Score
Medium

Opennetworking develops software infrastructure for telecommunications and software-defined networking environments, with a focused product line centered on ONOS (Open Networking Operating System), its controller platform, and related libraries such as libfluid_msg and User Plane Function components. The vendor's vulnerabilities concentrate in a modestly represented but prominent footprint and recur through weakness classes reflecting parsing and resource-management complexity inherent to network-control software: out-of-bounds reads, NULL pointer dereferences, unchecked return values leading to NULL-pointer conditions, incorrect control-flow logic, and uncontrolled resource consumption. A meaningful share of disclosed vulnerabilities reach serious severity levels, reflecting the criticality of control-plane and management-interface code in carrier networks. Defenders operating SDN infrastructure or telecommunications deployments built around ONOS should inventory affected versions and prioritize updates to network-control components; live exploitation, KEV status, and detailed severity breakdowns are shown alongside this summary.

FAUCET AI Generated
63
Total CVEs
More Total CVEs than 99% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opennetworking over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2018
8 years ago
Most Recent CVE
Dec 18, 2025
218 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-29606CRITICAL
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers
Apr 20, 20239.831NONO
CVE-2018-1000155CRITICAL
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply messa
May 24, 20189.831NONO
CVE-2022-29604CRITICAL
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of ca
Apr 20, 20239.830NONO
CVE-2023-41591CRITICAL
An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-middle attack on communications between fake a
May 29, 20259.829NONO
CVE-2025-65568HIGH
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment
Dec 18, 20257.527NONO
CVE-2025-65567HIGH
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Sess
Dec 18, 20257.525NONO
CVE-2025-65565HIGH
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session
Dec 18, 20257.525NONO
CVE-2025-65564HIGH
A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is
Dec 18, 20257.525NONO
CVE-2025-65563HIGH
A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Asso
Dec 18, 20257.525NONO
CVE-2025-29310CRITICAL
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary
Mar 24, 20259.825NONO
View all 63 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products63 CVEs
11%
79%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.6%)
Network62 (98.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (98.4%)
High1 (1.6%)
Unknown0 (0.0%)
User Interaction
None61 (96.8%)
Unknown0 (0.0%)
Required2 (3.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None63 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opennetworking.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opennetworking — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opennetworking's Products

View all 2 CNAs →

Top CWEs