ZeroHour

CVE-2018-12691

CVSS 3.0
6.8 medium
EPSS
<1%p51
Published
()
Modified
Description

Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection.

Vendors
onosproject
Products
onos
Weakness
CWE-362
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.