PT-2024-27246 · Unknown · Opendaylight

Published

2024-05-31

·

Updated

2024-12-16

·

CVE-2024-37018

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenDaylight version 0.15.3
Description The issue allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.
Recommendations For OpenDaylight version 0.15.3, consider restricting access to API endpoints that handle discovery packets to minimize the risk of exploitation. As a temporary workaround, avoid using API requests that can manipulate the path of discovery packets until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-37018

Affected Products

Opendaylight