Записи OpenDayLight
17 опубликованных записей вендора opendaylight.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 17,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation4
- CWE-400 Uncontrolled Resource Consumption2
- CWE-476 NULL Pointer Dereference2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-254 7PK - Security Features1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-1132Эксплойта нет | A flaw was found in Opendaylight's SDNInterfaceapp (SDNI).opendaylight · sdninterfaceapp · CWE-89 | Критическая9,8 | — | 2,8 % | 20 июн. 2018 г. |
40В плане | CVE-2015-1778Эксплойта нет | The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any usernameopendaylight · opendaylight · CWE-287 | Критическая9,8 | — | 2,7 % | 27 июн. 2017 г. |
39Наблюдать | CVE-2018-1078Эксплойта нет | OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should opendaylight · openflow · CWE-20 | Критическая9,8 | — | 1,2 % | 16 мар. 2018 г. |
36Наблюдать | CVE-2014-8149Эксплойта нет | OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.opendaylight · defense4all · CWE-20 | Высокая8,8 | — | 1,8 % | 27 июн. 2017 г. |
31Наблюдать | CVE-2015-1611Эксплойта нет | OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related toopendaylight · openflow · CWE-20 | Высокая7,5 | — | 2,1 % | 4 апр. 2017 г. |
31Наблюдать | CVE-2015-1612Эксплойта нет | OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related toopendaylight · openflow · CWE-20 | Высокая7,5 | — | 2,1 % | 4 апр. 2017 г. |
30Наблюдать | CVE-2017-1000411Эксплойта нет | OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expiropendaylight · opendaylight · CWE-404 | Высокая7,5 | — | 1,6 % | 31 янв. 2018 г. |
30Наблюдать | CVE-2017-1000361Эксплойта нет | DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight.opendaylight · opendaylight | Высокая7,5 | — | 1,4 % | 24 апр. 2017 г. |
30Наблюдать | CVE-2017-1000357Эксплойта нет | Denial of Service attack when the switch rejects to receive packets from the controller.opendaylight · opendaylight · CWE-400 | Высокая7,5 | — | 1,4 % | 24 апр. 2017 г. |
30Наблюдать | CVE-2017-1000406Эксплойта нет | OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cacheopendaylight · karaf · CWE-254 | Высокая7,5 | — | 1,1 % | 30 нояб. 2017 г. |
30Наблюдать | CVE-2024-46943Эксплойта нет | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3.opendaylight · authentication\, authorization and accounting · CWE-520 | Высокая7,5 | — | 0,6 % | 15 сент. 2024 г. |
28Наблюдать | CVE-2014-5035Эксплойта нет | The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjopendaylight · opendaylight | Средняя6,8 | — | 2,5 % | 26 авг. 2014 г. |
26Наблюдать | CVE-2017-1000358Эксплойта нет | Controller throws an exception and does not allow user to add subsequent flow for a particular switch.opendaylight · opendaylight · CWE-476 | Средняя6,5 | — | 1,1 % | 24 апр. 2017 г. |
26Наблюдать | CVE-2024-46942Эксплойта нет | In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entriesopendaylight · model-driven service abstraction layer · CWE-285 | Средняя6,5 | — | 0,4 % | 15 сент. 2024 г. |
21Наблюдать | CVE-2015-1610Эксплойта нет | hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topolopendaylight · l2switch · CWE-264 | Средняя5,3 | — | 1,4 % | 20 мар. 2017 г. |
21Наблюдать | CVE-2017-1000360Эксплойта нет | StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql.opendaylight · opendaylight · CWE-476 | Средняя5,3 | — | 1,3 % | 24 апр. 2017 г. |
21Наблюдать | CVE-2017-1000359Эксплойта нет | Java out of memory error and significant increase in resource consumption.opendaylight · opendaylight · CWE-400 | Средняя5,3 | — | 1,3 % | 24 апр. 2017 г. |
- CVE-2018-113240В плане
A flaw was found in Opendaylight's SDNInterfaceapp (SDNI).
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %opendaylight · sdninterfaceapp20 июн. 2018 г.
- CVE-2015-177840В плане
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %opendaylight · opendaylight27 июн. 2017 г.
- CVE-2018-107839Наблюдать
OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opendaylight · openflow16 мар. 2018 г.
- CVE-2014-814936Наблюдать
OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %opendaylight · defense4all27 июн. 2017 г.
- CVE-2015-161131Наблюдать
OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opendaylight · openflow4 апр. 2017 г.
- CVE-2015-161231Наблюдать
OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opendaylight · openflow4 апр. 2017 г.
- CVE-2017-100041130Наблюдать
OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expir
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %opendaylight · opendaylight31 янв. 2018 г.
- CVE-2017-100036130Наблюдать
DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opendaylight · opendaylight24 апр. 2017 г.
- CVE-2017-100035730Наблюдать
Denial of Service attack when the switch rejects to receive packets from the controller.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opendaylight · opendaylight24 апр. 2017 г.
- CVE-2017-100040630Наблюдать
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opendaylight · karaf30 нояб. 2017 г.
- CVE-2024-4694330Наблюдать
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %opendaylight · authentication\, authorization and accounting15 сент. 2024 г.
- CVE-2014-503528Наблюдать
The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conj
СредняяCVSS 6,8Эксплойта нетEPSS 2 %opendaylight · opendaylight26 авг. 2014 г.
- CVE-2017-100035826Наблюдать
Controller throws an exception and does not allow user to add subsequent flow for a particular switch.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %opendaylight · opendaylight24 апр. 2017 г.
- CVE-2024-4694226Наблюдать
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries
СредняяCVSS 6,5Эксплойта нетEPSS 0 %opendaylight · model-driven service abstraction layer15 сент. 2024 г.
- CVE-2015-161021Наблюдать
hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topol
СредняяCVSS 5,3Эксплойта нетEPSS 1 %opendaylight · l2switch20 мар. 2017 г.
- CVE-2017-100036021Наблюдать
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %opendaylight · opendaylight24 апр. 2017 г.
- CVE-2017-100035921Наблюдать
Java out of memory error and significant increase in resource consumption.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %opendaylight · opendaylight24 апр. 2017 г.