An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Saber-Berserker/10c9d548b38fa988310d90b8314e3129. | Broken Link |
Configurations
History
No history.
Information
Published : 2025-03-24 21:15
Updated : 2025-04-01 19:51
NVD link : CVE-2025-29310
Mitre link : CVE-2025-29310
CVE.ORG link : CVE-2025-29310
JSON object : View
Products Affected
opennetworking
- onos
CWE
CWE-502
Deserialization of Untrusted Data
