CRITICAL🇵🇱 Wersja polska

CVE-2025-29312

CVSS 9.1v3.1pub. 2025-03-24upd. 2025-04-01

An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.

🤖 AI Analysis
How it works

An unauthenticated attacker remotely manipulates the network link type in ONOS, changing it from indirect to direct mode. Improper handling of this change (CWE-670 – incorrectly implemented control logic) causes the ONOS controller to process the network state in a manner inconsistent with expectations, resulting in unexpected behavior of devices connected to legacy switches. The attack vector is network-based, requires no privileges or user interaction.

Impact

An attacker can compromise the integrity of network configuration and cause disruption to the availability of devices connected to legacy switches managed by the ONOS controller, which may lead to network infrastructure outages.

Mitigation & patch

Patches available from the vendor should be applied according to references. As a temporary workaround, it is recommended to restrict network access to the ONOS management interface exclusively to trusted hosts and to monitor changes in link types on the controller.

Who is affected

ONOS (Open Network Operating System) version 2.7.0 by Opennetworking

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Opennetworking Onos

    APP
    Opennetworking
    2.7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-41591CRITICAL9.8PL ✓same product

ONOS v2.7.0 — fałszowanie adresów IP/MAC umożliwiające atak man-in-the-middle

CVE-2025-29310CRITICAL9.8PL ✓same product

Niebezpieczna deserializacja pakietów LLDP w ONOS v2.7.0 (RCE)

CVE-2022-29604CRITICAL9.8PL ✓same product

ONOS 2.5.1 — błędna obsługa wielkości liter w ID urządzeń powoduje niespójność reguł sieciowych

CVE-2022-29606CRITICAL9.8PL ✓same product

ONOS: Nieprawidłowa obsługa dużych numerów portów w mechanizmie Intent

CVE-2025-29311HIGH7.5same product

Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a brut...