Opendaylight

Opendaylight

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.93%
  • Veröffentlicht 31.01.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:40

OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of CONFIG DATASTORE which leads to CONTROLLER shutdown. If multiple diff...

  • EPSS 3%
  • Veröffentlicht 27.06.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 24.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight ve...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 24.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is affected by this flaw.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 24.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 24.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and ...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 24.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight is vulnerable to this flaw. Version: The tested versions are OpenDayli...

  • EPSS 0.78%
  • Veröffentlicht 26.08.2014 14:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference in an XML-RPC message, related to an XML External Entity (XXE) issue.