Description
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8021 | An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information. |
References
History
Tue, 01 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opennetworking
Opennetworking onos |
|
| CPEs | cpe:2.3:a:opennetworking:onos:2.7.0:-:*:*:*:*:*:* | |
| Vendors & Products |
Opennetworking
Opennetworking onos |
Wed, 26 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
cvssV3_1
|
Mon, 24 Mar 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-26T14:38:01.406Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29310
Updated: 2025-03-26T13:39:40.852Z
Status : Analyzed
Published: 2025-03-24T21:15:17.893
Modified: 2025-04-01T19:51:09.180
Link: CVE-2025-29310
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD