Description
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB service ONOS controller via a normal switch.. This attack appear to be exploitable via the attacker should be able to control or forge a switch in the network..
Remediation
References
http://gms.cl0udz.com/OVSDB_DOS.pdf
https://gerrit.onosproject.org/#/c/18926/
Related Vulnerabilities
CVE-2022-43416 Vulnerability in maven package org.jenkins-ci.plugins:katalon
CVE-2018-3752 Vulnerability in npm package merge-options
CVE-2022-45208 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2023-34434 Vulnerability in maven package org.apache.inlong:manager-pojo
CVE-2020-13943 Vulnerability in maven package org.apache.tomcat:tomcat-coyote