Event Handling Flaw in Open Network Operating System by ONOS
CVE-2019-16297
7.5HIGH
What is CVE-2019-16297?
An event handling issue has been identified in the Open Network Operating System (ONOS) version 1.14, specifically within the P4 tutorial application (org.onosproject.p4tutorial). The host event listener fails to effectively manage crucial event types such as HOST_MOVED, HOST_REMOVED, and HOST_UPDATED. This oversight, when interfaced with other applications, may result in unintended code execution, potentially compromising the intended functionality of the network system.