Access Control Flaw in Open Network Operating System by ONOS
CVE-2019-16300

7.5HIGH

Key Information:

Vendor
Linux
Vendor
CVE Published:
20 February 2020

Summary

An issue was identified in Open Network Operating System (ONOS) version 1.14 concerning the access control application. The host event listener does not process certain event types, specifically HOST_REMOVED. This oversight, when combined with other applications, may prevent expected code execution, potentially affecting the system's ability to respond correctly to network events and jeopardizing intended security measures.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.