Improper Input Validation in ONOS SDN Controller by The Linux Foundation
CVE-2019-1010245

9.8CRITICAL

Key Information:

Vendor
Linux
Vendor
CVE Published:
19 July 2019

Summary

The ONOS SDN Controller, developed by The Linux Foundation, suffers from a vulnerability due to improper input validation in the YangLiveCompilerManager component. This flaw allows remote attackers to execute arbitrary commands on the controller through network connectivity. It is crucial for users of affected versions to upgrade to the fixed version 1.15 to mitigate this risk and enhance system security. Comprehensive knowledge of the underlying code, specifically in the apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java file, is essential for addressing this issue.

Affected Version(s)

ONOS SDN Controller 1.15 and earlier versions [fixed: 1.15]

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.