Lucene search

K
nvd[email protected]NVD:CVE-2022-24109
HistoryApr 20, 2023 - 1:15 p.m.

CVE-2022-24109

2023-04-2013:15:06
CWE-400
web.nvd.nist.gov
5
onos
security vulnerability
duplicate intent
remote attacker
flow rules

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

EPSS

0.002

Percentile

57.6%

An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent with a different key, and then remove the duplicate one. This will remove the flow rules of the intent, even though the intent still exists in the controller.

Affected configurations

Nvd
Node
opennetworkingonosMatch2.5.1
VendorProductVersionCPE
opennetworkingonos2.5.1cpe:2.3:a:opennetworking:onos:2.5.1:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

EPSS

0.002

Percentile

57.6%

Related for NVD:CVE-2022-24109