An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://wiki.onosproject.org/display/ONOS/Intent+Framework | product |
https://www.usenix.org/system/files/sec23fall-prepub-285_kim-jiwon.pdf | third party advisory exploit technical description |