ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB service ONOS controller via a normal switch.. This attack appear to be exploitable via the attacker should be able to control or forge a switch in the network..
References
Link Resource
http://gms.cl0udz.com/OVSDB_DOS.pdf Exploit Third Party Advisory
https://gerrit.onosproject.org/#/c/18926/ Issue Tracking Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:59

Updated: 2022-10-03T16:21:59

Reserved: 2018-06-28T00:00:00


Link: CVE-2018-1000615

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-07-09T20:29:00.423

Modified: 2020-08-24T17:37:01.140


Link: CVE-2018-1000615

JSON object: View

cve-icon Redhat Information

No data.