CVE-2022-29605
HIGHONOS 2.5.1 - Always-Incorrect Control Flow Implementation in IntentManager
Title source: llmDescription
An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of an intent into an OpenFlow 1.0 switch that does not support IPv6. Improper handling of the difference in capabilities of the intent and switch is misleading to a network operator.
References (2)
Core 2
Core References
Exploit, Technical Description, Third Party Advisory
https://www.usenix.org/system/files/sec23fall-prepub-285_kim-jiwon.pdf
Scores
CVSS v3
7.5
EPSS
0.0065
EPSS Percentile
46.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-670
Status
published
Products (1)
opennetworking/onos
2.5.1
Published
Apr 20, 2023
Tracked Since
Feb 18, 2026