CVE-2018-1000616

CRITICAL

ONOS < 1.13.1 - XML External Entity Injection in XmlConfigParser

Title source: llm
STIX 2.1

Description

ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_confirm
https://gerrit.onosproject.org/#/c/18894/
Exploit, Third Party Advisory x_refsource_misc
http://gms.cl0udz.com/Openconfig_xxe.pdf

Scores

CVSS v3 9.8
EPSS 0.0141
EPSS Percentile 69.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (1)
onosproject/onos < 1.13.1
Published Jul 09, 2018
Tracked Since Feb 18, 2026