First published: Thu Feb 20 2020(Updated: )
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the mobility application (org.onosproject.mobility), the host event listener does not handle the following event types: HOST_ADDED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this could lead to the absence of intended code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Foundation Open Network Operating System | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16299 has been classified as a medium severity vulnerability.
To fix CVE-2019-16299, update to the latest version of Open Network Operating System that addresses this issue.
CVE-2019-16299 affects the mobility application component in Open Network Operating System version 1.14.
CVE-2019-16299 may lead to ineffective handling of host events, potentially impacting network management.
Yes, CVE-2019-16299 could be exploited in a production environment when combined with other applications.