7.5

CVE-2015-1611

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to "fake LLDP injection."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpendaylightOpenflow Version- SwPlatformopendaylight
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.07% 0.79
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.internetsociety.org/sites/default/files/10_4_2.pdf
Technical Description
http://www.securityfocus.com/bid/73254
Third Party Advisory
VDB Entry
https://cloudrouter.org/security/
Third Party Advisory
https://git.opendaylight.org/gerrit/#/c/16193/
Patch
Third Party Advisory
Issue Tracking
https://git.opendaylight.org/gerrit/#/c/16208/
Patch
Third Party Advisory
Issue Tracking
https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-2015-1611_CVE-2015-1612_openflowplugin:_topology_spoofing_via_LLDP
Patch
Third Party Advisory