Lucene search

K
nvd[email protected]NVD:CVE-2021-38363
HistoryApr 20, 2023 - 1:15 p.m.

CVE-2021-38363

2023-04-2013:15:06
CWE-755
web.nvd.nist.gov
2
cve-2021-38363
memory storage
deletion issue
intent cleanup

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.002

Percentile

58.9%

An issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendingMap (in memory) forever. Deletion is possible neither by a user nor by the intermittent Intent Cleanup process.

Affected configurations

Nvd
Node
opennetworkingonosMatch2.5.1
VendorProductVersionCPE
opennetworkingonos2.5.1cpe:2.3:a:opennetworking:onos:2.5.1:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.002

Percentile

58.9%

Related for NVD:CVE-2021-38363