Skip to main content

Vendor archive

opendaylight CVEs

Beta · best-effort

17 CVEs tagged to vendor opendaylight2 Critical, 9 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2018-1132

Published Jun 20, 2018

A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1078

Published Mar 16, 2018

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly bei…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000406

Published Nov 30, 2017

OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1778

Published Jun 27, 2017

The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8149

Published Jun 27, 2017

OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000361

Published Apr 24, 2017

DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000360

Published Apr 24, 2017

StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerab…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000359

Published Apr 24, 2017

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are Open…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000358

Published Apr 24, 2017

Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: Op…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000357

Published Apr 24, 2017

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the featu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1612

Published Apr 4, 2017

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to the reuse of LLDP packets, aka "LLDP R…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1611

Published Apr 4, 2017

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to "fake LLDP injection."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1610

Published Mar 20, 2017

hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topology spoofing."

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5035

Published Aug 26, 2014

The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference in an…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1