CVE-2019-1010252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
18/07/2019
Last modified:
29/07/2019

Description

The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management and connectivity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linuxfoundation:open_network_operating_system:*:*:*:*:*:*:*:* 2.0.0 (including)