First published: Thu Feb 20 2020(Updated: )
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the P4 tutorial application (org.onosproject.p4tutorial), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Foundation Open Network Operating System | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16297 has not been assigned a specific CVSS score but indicates a significant issue within ONOS 1.14's P4 tutorial application.
To mitigate CVE-2019-16297, consider updating to a later version of Open Network Operating System that addresses the event listener handling issue.
CVE-2019-16297 affects the Open Network Operating System 1.14, specifically the P4 tutorial application.
CVE-2019-16297 fails to handle HOST_MOVED, HOST_REMOVED, and HOST_UPDATED event types.
CVE-2019-16297 could lead to unexpected behavior in network applications that rely on accurate host event handling.