PT-2023-12979 · Onos · Onos
Published
2023-04-20
·
Updated
2023-05-04
·
CVE-2022-29604
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ONOS version 2.5.1
Description
An issue was discovered in ONOS where an intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. This occurs due to improper handling of case sensitivity, causing inconsistency between intent and flow rules in the network.
Recommendations
For ONOS version 2.5.1, consider updating to a newer version that properly handles case sensitivity in device IDs to resolve the issue. As a temporary workaround, ensure that device IDs are entered consistently, either all in uppercase or all in lowercase, to minimize inconsistencies between intent and flow rules.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onos