PT-2019-11524 · Onos · Onos Sdn Controller
Published
2019-07-19
·
Updated
2021-07-21
·
CVE-2019-1010245
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ONOS SDN Controller versions prior to 1.15
Description:
The issue is related to improper input validation, allowing a remote attacker to execute arbitrary commands on the controller. The component affected is the YangLiveCompilerManager.java file. The attack vector is through network connectivity.
Recommendations:
For versions prior to 1.15, update to version 1.15 to resolve the issue. As a temporary workaround, consider restricting network connectivity to the controller until the update is applied.
Exploit
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onos Sdn Controller