CVE-2024-37018

The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.
Configurations

No configuration.

History

05 Aug 2024, 16:35

Type Values Removed Values Added
CWE CWE-648
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
Summary
  • (es) El controlador OpenDaylight 0.15.3 permite el envenenamiento de la topología a través de solicitudes API porque una aplicación puede manipular la ruta que toman los paquetes de descubrimiento.

31 May 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-31 01:15

Updated : 2024-08-05 16:35


NVD link : CVE-2024-37018

Mitre link : CVE-2024-37018

CVE.ORG link : CVE-2024-37018


JSON object : View

Products Affected

No product.

CWE
CWE-648

Incorrect Use of Privileged APIs