Vulnerabilities > Opennetworking

DATE CVE VULNERABILITY TITLE RISK
2018-07-23 CVE-2018-1999020 Path Traversal vulnerability in Opennetworking Onos
Open Networking Foundation (ONF) ONOS version 1.13.2 and earlier version contains a Directory Traversal vulnerability in core/common/src/main/java/org/onosproject/common/app/ApplicationArchive.java line 35 that can result in arbitrary file deletion (overwrite).
local
low complexity
opennetworking CWE-22
5.5
2018-05-24 CVE-2018-1000155 Incorrect Authorization vulnerability in Opennetworking Openflow
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the controller.
network
low complexity
opennetworking CWE-863
critical
9.8