PT-2025-12710 · Opendaylight · Opendaylight Service Function Chaining (Sfc) Subproject

Published

2025-03-24

·

Updated

2025-03-25

·

CVE-2025-29313

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenDaylight Service Function Chaining (SFC) Subproject versions Sodium-SR4 and below
Description The issue is related to the use of incorrectly resolved names or references, which can lead to a Denial of Service (DoS). This allows attackers to cause service disruptions.
Recommendations For versions Sodium-SR4 and below, consider implementing additional validation for names and references to prevent incorrect resolutions until a patch is available. As a temporary workaround, restrict access to sensitive components of the OpenDaylight Service Function Chaining (SFC) Subproject to minimize the risk of exploitation.

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29313
GHSA-V3VP-FG2V-G7Q4

Affected Products

Opendaylight Service Function Chaining (Sfc) Subproject