Onos
Vendor:
First CVE: Jul 23, 2018 · Active for 8 years
19
Total CVEs
More Total CVEs than 95% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Onos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 23, 2018
8 years ago
Most Recent CVE
May 29, 2025
425 days ago
CVE Severity & Scoring
Onos19 CVEs
37%
37%
26%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (94.7%)
High1 (5.3%)
Unknown0 (0.0%)
User Interaction
None17 (89.5%)
Unknown0 (0.0%)
Required2 (10.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None19 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29606CRITICAL An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers | Apr 20, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-29604CRITICAL An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of ca | Apr 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-41591CRITICAL An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-middle attack on communications between fake a | May 29, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-29310CRITICAL An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary | Mar 24, 2025 | 9.8 | 25 | NO | NO |
CVE-2021-38363HIGH An issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendingMap (in memory) forever. Deletion is possible ne | Apr 20, 2023 | 7.5 | 25 | NO | NO |
CVE-2025-29312CRITICAL An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct. | Mar 24, 2025 | 9.1 | 24 | NO | NO |
CVE-2022-29608HIGH An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an invalid flow rule, causing a network loop. | Apr 20, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-29607HIGH An issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source and destination shows the INSTALLED state without any flow rule. Improper handling | Apr 20, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-24035HIGH An issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g., link failure). In combination with othe | Apr 20, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-38364MEDIUM An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote attacker can install or remove a new intent, and consequently m | Apr 20, 2023 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Onos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.7.0 | 5 | 8.4 | 0.4% | 0 | 0 |
| 2.5.1 | 11 | 7.3 | 0.8% | 0 | 0 |