PT-2019-11524 · Onos · Onos Sdn Controller

Published

2019-07-19

·

Updated

2021-07-21

·

CVE-2019-1010245

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ONOS SDN Controller versions prior to 1.15
Description: The issue is related to improper input validation, allowing a remote attacker to execute arbitrary commands on the controller. The component affected is the YangLiveCompilerManager.java file. The attack vector is through network connectivity.
Recommendations: For versions prior to 1.15, update to version 1.15 to resolve the issue. As a temporary workaround, consider restricting network connectivity to the controller until the update is applied.

Exploit

Fix

OS Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1010245

Affected Products

Onos Sdn Controller