CVE-2018-12691: Onosproject Onos
Medium severity, CVSS 6.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection.
Affected products
- Onosproject Onos: up to and including 1.13.0
Published 2018-07-05. Last modified 2026-06-17.