Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sdninterfaceapp CRITICAL 9.8
CVE-2018-1132

A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the c…

No fix yet
Fix from $2,300 2018-06-20
Openflow CRITICAL 9.8
CVE-2018-1078

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expire…

Mitigation only
Fix from $2,300 2018-03-16
Opendaylight HIGH 7.5
CVE-2017-1000411

OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows…

Mitigation only
Fix from $1,950 2018-01-31
Karaf HIGH 7.5
CVE-2017-1000406

OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manua…

Mitigation only
Fix from $1,950 2017-11-30
Opendaylight HIGH 7.5
CVE-2017-1000357

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2swi…

No fix yet
Fix from $1,950 2017-04-24
Opendaylight HIGH 7.5
CVE-2017-1000361

DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU reso…

No fix yet
Fix from $1,950 2017-04-24
Opendaylight MEDIUM 6.5
CVE-2017-1000358

Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature c…

No fix yet
Fix from $1,600 2017-04-24
Opendaylight MEDIUM 5.3
CVE-2017-1000359

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version…

No fix yet
Fix from $1,600 2017-04-24
Opendaylight MEDIUM 5.3
CVE-2017-1000360

StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDayli…

No fix yet
Fix from $1,600 2017-04-24
L2switch MEDIUM 5.3
CVE-2015-1610

hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topology spoof…

Mitigation only
Fix from $1,600 2017-03-20
Opendaylight MEDIUM 6.8
CVE-2014-5035

The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction w…

No fix yet
Fix from $1,600 2014-08-26