Opennetworking
48 CVEs tracked since 2023. Since Apr 2023, none of them reached CISA KEV.
Opennetworking CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-04 | 11 | 0 |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | 37 | 0 |
Products
The products that kept showing up in Opennetworking's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Opennetworking.
- CVE-2025-65568A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment Request that incl...7.5
- CVE-2025-65563A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Req...7.5
- CVE-2025-65565A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session Establishment Re...7.5
- CVE-2025-65567A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Session Establishment...7.5
- CVE-2025-65564A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the manda...7.5
- CVE-2024-53423An issue in Open Network Foundation ONOS v2.7.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted packets.5.6
- CVE-2023-41591An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-middle attack on communications between fake and real hosts.9.8
- CVE-2025-29312An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.9.1
- CVE-2025-29311Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted ...7.5
- CVE-2025-29310An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or acces...9.8
- CVE-2024-48809An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component of the sdran-in-a-box, specifica...7.5
- CVE-2024-31198Out-of-bounds Read in libfluid_msg library5.3
- CVE-2024-31197Improper Null Termination in libfluid_msg library5.3
- CVE-2024-31196NULL Pointer Dereference in libfluid_msg library5.3
- CVE-2024-31195Out-of-bounds Read in libfluid_msg library6.5
The record
- Peak rank
- #19 in Sep 2024
- Busiest month shown
- Sep 2024, 37 CVEs
- Months with a KEV entry
- 0 since Apr 2023
- Monthly snapshots
- 2 since 2023