CVE-2018-1999020

UnknownEPSS 1.28%

Last modified

CVE-2018-1999020 is a vulnerability of currently unknown severity. Open Networking Foundation (ONF) ONOS version 1.13.2 and earlier version contains a Directory Traversal vulnerability in core/common/src/main/java/org/onosproject/common/app/ApplicationArchive.java line 35 that can result in arbitrary file deletion (overwrite). This attack appear to be exploitable via a specially crafted zip file should be uploaded.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.

Description

Open Networking Foundation (ONF) ONOS version 1.13.2 and earlier version contains a Directory Traversal vulnerability in core/common/src/main/java/org/onosproject/common/app/ApplicationArchive.java line 35 that can result in arbitrary file deletion (overwrite). This attack appear to be exploitable via a specially crafted zip file should be uploaded.

Metrics

EPSS Probability
1.28%

66.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpennetworkingOnos<= 1.13.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1999020?
Open Networking Foundation (ONF) ONOS version 1.13.2 and earlier version contains a Directory Traversal vulnerability in core/common/src/main/java/org/onosproject/common/app/ApplicationArchive.java line 35 that can result in arbitrary file deletion (overwrite). This attack appear to be exploitable via a specially crafted zip file should be uploaded.
How severe is CVE-2018-1999020?
Severity scoring for CVE-2018-1999020 is pending analysis. The EPSS model estimates a 1.28% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1999020?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1999020?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST