Lucene search

K

Opendaylight Security Vulnerabilities

cve
cve

CVE-2014-5035

The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference in an XML-RPC message, related to an XML External Entity (XXE) issue.

6.9AI Score

0.008EPSS

2014-08-26 02:55 PM
23
cve
cve

CVE-2015-1778

The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.

9.8CVSS

9.6AI Score

0.005EPSS

2017-06-27 08:29 PM
25
cve
cve

CVE-2015-1857

The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.

5.3CVSS

5.1AI Score

0.002EPSS

2018-04-27 04:29 PM
24
2
cve
cve

CVE-2017-1000357

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight versions 3.3 (Lithium-SR3), 3.4 (Lithium-SR4), 4.0 ...

7.5CVSS

7.4AI Score

0.001EPSS

2017-04-24 04:59 PM
35
cve
cve

CVE-2017-1000358

Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is affected by this flaw.

6.5CVSS

6.4AI Score

0.001EPSS

2022-10-03 04:23 PM
36
cve
cve

CVE-2017-1000359

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.

5.3CVSS

5.2AI Score

0.001EPSS

2022-10-03 04:23 PM
30
cve
cve

CVE-2017-1000360

StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.

5.3CVSS

5.2AI Score

0.001EPSS

2022-10-03 04:23 PM
32
cve
cve

CVE-2017-1000361

DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.

7.5CVSS

7.5AI Score

0.002EPSS

2022-10-03 04:23 PM
30
cve
cve

CVE-2017-1000411

OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of CONFIG DATASTORE which leads to CONTROLLER shutdown. If multiple different flows with 'idle-timeout' and 'hard-timeout...

7.5CVSS

7.5AI Score

0.001EPSS

2018-01-31 02:29 PM
33
cve
cve

CVE-2018-1078

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.

9.8CVSS

9.3AI Score

0.002EPSS

2018-03-16 08:29 PM
31
cve
cve

CVE-2022-45930

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface.

7.5CVSS

7.9AI Score

0.001EPSS

2022-11-27 03:15 AM
33
10
cve
cve

CVE-2022-45931

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used.

7.5CVSS

7.9AI Score

0.001EPSS

2022-11-27 03:15 AM
39
8
cve
cve

CVE-2022-45932

A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

7.5CVSS

7.9AI Score

0.001EPSS

2022-11-27 03:15 AM
34
6