OpenDayLight kayıtları
opendaylight üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %17,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation4
- CWE-400 Uncontrolled Resource Consumption2
- CWE-476 NULL Pointer Dereference2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-254 7PK - Security Features1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-1132İstismar yok | A flaw was found in Opendaylight's SDNInterfaceapp (SDNI).opendaylight · sdninterfaceapp · CWE-89 | Kritik9,8 | — | %2,8 | 20 Haz 2018 |
40Planlayın | CVE-2015-1778İstismar yok | The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any usernameopendaylight · opendaylight · CWE-287 | Kritik9,8 | — | %2,7 | 27 Haz 2017 |
39İzleyin | CVE-2018-1078İstismar yok | OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should opendaylight · openflow · CWE-20 | Kritik9,8 | — | %1,2 | 16 Mar 2018 |
36İzleyin | CVE-2014-8149İstismar yok | OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.opendaylight · defense4all · CWE-20 | Yüksek8,8 | — | %1,8 | 27 Haz 2017 |
31İzleyin | CVE-2015-1611İstismar yok | OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related toopendaylight · openflow · CWE-20 | Yüksek7,5 | — | %2,1 | 4 Nis 2017 |
31İzleyin | CVE-2015-1612İstismar yok | OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related toopendaylight · openflow · CWE-20 | Yüksek7,5 | — | %2,1 | 4 Nis 2017 |
30İzleyin | CVE-2017-1000411İstismar yok | OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expiropendaylight · opendaylight · CWE-404 | Yüksek7,5 | — | %1,6 | 31 Oca 2018 |
30İzleyin | CVE-2017-1000361İstismar yok | DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight.opendaylight · opendaylight | Yüksek7,5 | — | %1,4 | 24 Nis 2017 |
30İzleyin | CVE-2017-1000357İstismar yok | Denial of Service attack when the switch rejects to receive packets from the controller.opendaylight · opendaylight · CWE-400 | Yüksek7,5 | — | %1,4 | 24 Nis 2017 |
30İzleyin | CVE-2017-1000406İstismar yok | OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cacheopendaylight · karaf · CWE-254 | Yüksek7,5 | — | %1,1 | 30 Kas 2017 |
30İzleyin | CVE-2024-46943İstismar yok | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3.opendaylight · authentication\, authorization and accounting · CWE-520 | Yüksek7,5 | — | %0,6 | 15 Eyl 2024 |
28İzleyin | CVE-2014-5035İstismar yok | The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjopendaylight · opendaylight | Orta6,8 | — | %2,5 | 26 Ağu 2014 |
26İzleyin | CVE-2017-1000358İstismar yok | Controller throws an exception and does not allow user to add subsequent flow for a particular switch.opendaylight · opendaylight · CWE-476 | Orta6,5 | — | %1,1 | 24 Nis 2017 |
26İzleyin | CVE-2024-46942İstismar yok | In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entriesopendaylight · model-driven service abstraction layer · CWE-285 | Orta6,5 | — | %0,4 | 15 Eyl 2024 |
21İzleyin | CVE-2015-1610İstismar yok | hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topolopendaylight · l2switch · CWE-264 | Orta5,3 | — | %1,4 | 20 Mar 2017 |
21İzleyin | CVE-2017-1000360İstismar yok | StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql.opendaylight · opendaylight · CWE-476 | Orta5,3 | — | %1,3 | 24 Nis 2017 |
21İzleyin | CVE-2017-1000359İstismar yok | Java out of memory error and significant increase in resource consumption.opendaylight · opendaylight · CWE-400 | Orta5,3 | — | %1,3 | 24 Nis 2017 |
- CVE-2018-113240Planlayın
A flaw was found in Opendaylight's SDNInterfaceapp (SDNI).
KritikCVSS 9,8İstismar yokEPSS %3opendaylight · sdninterfaceapp20 Haz 2018
- CVE-2015-177840Planlayın
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username
KritikCVSS 9,8İstismar yokEPSS %3opendaylight · opendaylight27 Haz 2017
- CVE-2018-107839İzleyin
OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should
KritikCVSS 9,8İstismar yokEPSS %1opendaylight · openflow16 Mar 2018
- CVE-2014-814936İzleyin
OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.
YüksekCVSS 8,8İstismar yokEPSS %2opendaylight · defense4all27 Haz 2017
- CVE-2015-161131İzleyin
OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to
YüksekCVSS 7,5İstismar yokEPSS %2opendaylight · openflow4 Nis 2017
- CVE-2015-161231İzleyin
OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to
YüksekCVSS 7,5İstismar yokEPSS %2opendaylight · openflow4 Nis 2017
- CVE-2017-100041130İzleyin
OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expir
YüksekCVSS 7,5İstismar yokEPSS %2opendaylight · opendaylight31 Oca 2018
- CVE-2017-100036130İzleyin
DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight.
YüksekCVSS 7,5İstismar yokEPSS %1opendaylight · opendaylight24 Nis 2017
- CVE-2017-100035730İzleyin
Denial of Service attack when the switch rejects to receive packets from the controller.
YüksekCVSS 7,5İstismar yokEPSS %1opendaylight · opendaylight24 Nis 2017
- CVE-2017-100040630İzleyin
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache
YüksekCVSS 7,5İstismar yokEPSS %1opendaylight · karaf30 Kas 2017
- CVE-2024-4694330İzleyin
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3.
YüksekCVSS 7,5İstismar yokEPSS %1opendaylight · authentication\, authorization and accounting15 Eyl 2024
- CVE-2014-503528İzleyin
The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conj
OrtaCVSS 6,8İstismar yokEPSS %2opendaylight · opendaylight26 Ağu 2014
- CVE-2017-100035826İzleyin
Controller throws an exception and does not allow user to add subsequent flow for a particular switch.
OrtaCVSS 6,5İstismar yokEPSS %1opendaylight · opendaylight24 Nis 2017
- CVE-2024-4694226İzleyin
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries
OrtaCVSS 6,5İstismar yokEPSS %0opendaylight · model-driven service abstraction layer15 Eyl 2024
- CVE-2015-161021İzleyin
hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topol
OrtaCVSS 5,3İstismar yokEPSS %1opendaylight · l2switch20 Mar 2017
- CVE-2017-100036021İzleyin
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql.
OrtaCVSS 5,3İstismar yokEPSS %1opendaylight · opendaylight24 Nis 2017
- CVE-2017-100035921İzleyin
Java out of memory error and significant increase in resource consumption.
OrtaCVSS 5,3İstismar yokEPSS %1opendaylight · opendaylight24 Nis 2017