Event Handling Flaw in Open Network Operating System by ONOS
CVE-2019-16297

7.5HIGH

Key Information:

Vendor
Linux
Vendor
CVE Published:
20 February 2020

Summary

An event handling issue has been identified in the Open Network Operating System (ONOS) version 1.14, specifically within the P4 tutorial application (org.onosproject.p4tutorial). The host event listener fails to effectively manage crucial event types such as HOST_MOVED, HOST_REMOVED, and HOST_UPDATED. This oversight, when interfaced with other applications, may result in unintended code execution, potentially compromising the intended functionality of the network system.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.