CVE-2025-29311

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 24, 2025
Updated: Apr 1, 2025
CWE ID 331

Summary

CVE-2025-29311 is a vulnerability affecting onos v2.7.0 that allows attackers to obtain private keys through a bruteforce attack on the limited secret space in LLDP (Link Layer Discovery Protocol) packets. Attackers can leverage this vulnerability to create crafted LLDP packets, potentially leading to unauthorized access to network devices. This issue poses a significant risk, as LLDP is widely used in enterprise networks for device discovery and communication. It is recommended that affected organizations upgrade to a patched version of onos as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share