CVE-2017-1000411
- EPSS 0.93%
- Veröffentlicht 31.01.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:40
OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of CONFIG DATASTORE which leads to CONTROLLER shutdown. If multiple diff...
CVE-2015-1778
- EPSS 3%
- Veröffentlicht 27.06.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
CVE-2017-1000357
- EPSS 0.49%
- Veröffentlicht 24.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight ve...
CVE-2017-1000358
- EPSS 0.37%
- Veröffentlicht 24.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is affected by this flaw.
CVE-2017-1000359
- EPSS 0.45%
- Veröffentlicht 24.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.
CVE-2017-1000360
- EPSS 0.39%
- Veröffentlicht 24.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and ...
CVE-2017-1000361
- EPSS 0.49%
- Veröffentlicht 24.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight is vulnerable to this flaw. Version: The tested versions are OpenDayli...
CVE-2014-5035
- EPSS 0.78%
- Veröffentlicht 26.08.2014 14:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference in an XML-RPC message, related to an XML External Entity (XXE) issue.