CVE-2019-1010250: Input Validation
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is: network management and connectivity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1010250?
CVE-2019-1010250 has a moderate severity level due to the potential for unintended flow rule installation in network switches.
How do I fix CVE-2019-1010250?
To fix CVE-2019-1010250, update to a version of ONOS later than 2.0.0 that addresses the poor input validation issue.
Who is affected by CVE-2019-1010250?
CVE-2019-1010250 affects users of the Linux Foundation ONOS version 2.0.0 and earlier.
What components are involved in CVE-2019-1010250?
The createFlow() and createFlows() functions in FlowWebResource.java are involved in the vulnerability of CVE-2019-1010250.
What types of attacks can exploit CVE-2019-1010250?
CVE-2019-1010250 can be exploited by network administrators or attackers who inadvertently install unintended flow rules in the switch.