CVE-2019-16302: High severity linux foundation open network operating system vulnerability
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event listener does not handle the following event types: HOSTMOVED, HOSTUPDATED. In combination with other applications, this could lead to the absence of intended code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-16302?
CVE-2019-16302 has been assigned a medium severity rating due to its potential impact on host event handling.
How do I fix CVE-2019-16302?
To fix CVE-2019-16302, update to a newer version of ONOS that addresses the handling of HOST_MOVED and HOST_UPDATED events.
Which version of ONOS is affected by CVE-2019-16302?
CVE-2019-16302 affects the Open Network Operating System version 1.14.0.
What applications are involved with CVE-2019-16302?
CVE-2019-16302 involves the Ethernet VPN application within the ONOS platform.
What are the implications of CVE-2019-16302?
CVE-2019-16302 may lead to the absence of critical host event updates in networking scenarios, impacting overall system behavior.