Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Authentication\, Authorization And Accounting HIGH 7.5
CVE-2024-46943

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to i…

Fix: after 0.19.3
Fix from $1,950 2024-09-15
Model Driven Service Abstraction Layer MEDIUM 6.5
CVE-2024-46942

In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an Op…

Fix: after 13.0.1
Fix from $1,600 2024-09-15
Sdninterfaceapp CRITICAL 9.8
CVE-2018-1132

A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the c…

No fix yet
Fix from $2,300 2018-06-20
Openflow CRITICAL 9.8
CVE-2018-1078

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expire…

Mitigation only
Fix from $2,300 2018-03-16
Opendaylight HIGH 7.5
CVE-2017-1000411

OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows…

Mitigation only
Fix from $1,950 2018-01-31
Karaf HIGH 7.5
CVE-2017-1000406

OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manua…

Mitigation only
Fix from $1,950 2017-11-30
Opendaylight CRITICAL 9.8
CVE-2015-1778

The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and pass…

Patch available
Fix from $2,300 2017-06-27
Defense4all HIGH 8.8
CVE-2014-8149

OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.

Fix: after 1.1.0
Fix from $1,950 2017-06-27
Opendaylight HIGH 7.5
CVE-2017-1000357

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2swi…

No fix yet
Fix from $1,950 2017-04-24
Opendaylight HIGH 7.5
CVE-2017-1000361

DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU reso…

No fix yet
Fix from $1,950 2017-04-24
Opendaylight MEDIUM 6.5
CVE-2017-1000358

Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature c…

No fix yet
Fix from $1,600 2017-04-24
Opendaylight MEDIUM 5.3
CVE-2017-1000359

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version…

No fix yet
Fix from $1,600 2017-04-24
Opendaylight MEDIUM 5.3
CVE-2017-1000360

StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDayli…

No fix yet
Fix from $1,600 2017-04-24
Openflow HIGH 7.5
CVE-2015-1611

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to "fake LL…

Patch available
Fix from $1,950 2017-04-04
Openflow HIGH 7.5
CVE-2015-1612

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to the reus…

Patch available
Fix from $1,950 2017-04-04
L2switch MEDIUM 5.3
CVE-2015-1610

hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topology spoof…

Mitigation only
Fix from $1,600 2017-03-20
Opendaylight MEDIUM 6.8
CVE-2014-5035

The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction w…

No fix yet
Fix from $1,600 2014-08-26