CVE-2019-1010250 affects The Linux Foundation ONOS 2.0.0 and earlier, stemming from poor input validation in the createFlow() and createFlows() functions within the FlowWebResource.java RESTful service. This vulnerability allows a highly privileged network administrator, or an attacker with equivalent access, to install unintended flow rules on network switches. Rated Medium with a CVSSv3 score of 4.9, the attack requires network management access but is not complex to execute, potentially leading to high integrity impact without affecting confidentiality or availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0CPE matchmatch criteria | cpe:2.3:o:linuxfoundation:open_network_operating_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.