Integer Overflow Vulnerability in Linux Foundation ONOS Product
CVE-2019-1010249

4.9MEDIUM

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
18 July 2019

Summary

The Linux Foundation ONOS version 2.0.0 and earlier is susceptible to an integer overflow vulnerability in the createFlow() and createFlows() functions of the FlowWebResource.java file. This weakness may allow a network administrator or an attacker to inadvertently install unintended flow rules on the switch. The vulnerability arises during network management operations, which can jeopardize the integrity and functionality of network traffic control.

Affected Version(s)

ONOS 2.0.0 and earlier

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.