First published: Thu Feb 20 2020(Updated: )
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the access control application (org.onosproject.acl), the host event listener does not handle the following event types: HOST_REMOVED. In combination with other applications, this could lead to the absence of intended code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Foundation Open Network Operating System | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-16300 is classified as medium due to potential unintended code execution.
To fix CVE-2019-16300, you should upgrade to a later version of Open Network Operating System that addresses this vulnerability.
CVE-2019-16300 affects Open Network Operating System version 1.14.0.
CVE-2019-16300 is an access control vulnerability related to event handling.
Yes, CVE-2019-16300 can potentially lead to unauthorized code execution if exploited in combination with other vulnerabilities.