Security Advisory

CVE-2018-1000616

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-07-09 20:00:00
Last updated 2024-09-17 01:31:35
Assigner mitre
State PUBLISHED

Description

ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onosdriversutilitiessrcmainjavaorgonosprojectdriversutilitiesXmlConfigParser.java loadxml() that can result in An adversary can remotely launch XXE attacks on ONOS controller via an OpenConfig Terminal Device.. This attack appear to be exploitable via network connectivity.