CVE-2025-29311 Details
Description
Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets.
A vulnerability in the Link Layer Discovery Protocol (LLDP) packets used in ONOS version 2.7.0 allows attackers to obtain private keys through a brute-force attack. Exploitation of this vulnerability involves creating and sending crafted LLDP packets.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Saber-Berserker/790f2a75ae482df3fd0fce569f30504a; | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-331 | Insufficient Entropy | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| opennetworking onos | 2.7.0 - |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2025 | Initial Analysis | [email protected] |
| Mar 26, 2025 | CVE Modified | CISA-ADP |
| Mar 24, 2025 | New CVE Received | [email protected] |