CVE-2019-16298: High severity linux foundation open network operating system vulnerability
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual broadband network gateway application (org.onosproject.virtualbng), the host event listener does not handle the following event types: HOSTMOVED, HOSTREMOVED, HOSTUPDATED. In combination with other applications, this could lead to the absence of intended code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16298?
CVE-2019-16298 has a medium severity level due to improper event handling in the ONOS virtual broadband network gateway.
How do I fix CVE-2019-16298?
To fix CVE-2019-16298, update to a later version of the Open Network Operating System that addresses the event handling issues.
Which versions of ONOS are affected by CVE-2019-16298?
CVE-2019-16298 affects Open Network Operating System version 1.14.0.
What are the consequences of CVE-2019-16298?
The consequences of CVE-2019-16298 may include disruptions in network management due to unhandled host events.
Is CVE-2019-16298 exploitable remotely?
CVE-2019-16298 is not explicitly defined as exploitable remotely, but it may impact network operations depending on the system configuration.