CVE-2018-1000616
CRITICALONOS < 1.13.1 - XML External Entity Injection in XmlConfigParser
Title source: llmDescription
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity.
References (2)
Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_confirm
https://gerrit.onosproject.org/#/c/18894/
Exploit, Third Party Advisory x_refsource_misc
http://gms.cl0udz.com/Openconfig_xxe.pdf
Scores
CVSS v3
9.8
EPSS
0.0141
EPSS Percentile
69.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (1)
onosproject/onos
< 1.13.1
Published
Jul 09, 2018
Tracked Since
Feb 18, 2026