Improper Input Validation in ONOS SDN Controller by The Linux Foundation
CVE-2019-1010245
9.8CRITICAL
Summary
The ONOS SDN Controller, developed by The Linux Foundation, suffers from a vulnerability due to improper input validation in the YangLiveCompilerManager component. This flaw allows remote attackers to execute arbitrary commands on the controller through network connectivity. It is crucial for users of affected versions to upgrade to the fixed version 1.15 to mitigate this risk and enhance system security. Comprehensive knowledge of the underlying code, specifically in the apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java file, is essential for addressing this issue.
Affected Version(s)
ONOS SDN Controller 1.15 and earlier versions [fixed: 1.15]
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved