CVE-2019-1010249

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
18/07/2019
Last modified:
24/07/2019

Description

The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is: network management and connectivity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linuxfoundation:open_network_operating_system:*:*:*:*:*:*:*:* 2.0.0 (including)