CVE-2024-46943

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opendaylight:authentication\,_authorization_and_accounting:*:*:*:*:*:*:*:*

History

20 Sep 2024, 16:56

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:opendaylight:authentication\,_authorization_and_accounting:*:*:*:*:*:*:*:*
First Time Opendaylight
Opendaylight authentication\, Authorization And Accounting
References () https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html - () https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html - Release Notes
References () https://doi.org/10.48550/arXiv.2408.16940 - () https://doi.org/10.48550/arXiv.2408.16940 - Technical Description
References () https://lf-opendaylight.atlassian.net/browse/AAA-285 - () https://lf-opendaylight.atlassian.net/browse/AAA-285 - Issue Tracking, Vendor Advisory

17 Sep 2024, 15:35

Type Values Removed Values Added
CWE CWE-520
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

16 Sep 2024, 15:30

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en OpenDaylight Authentication, Authorization and Accounting (AAA) hasta la versión 0.19.3. Un controlador no autorizado puede unirse a un clúster para hacerse pasar por un par sin conexión, incluso si este controlador no autorizado no posee la información completa de configuración del clúster.

15 Sep 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-15 23:15

Updated : 2024-09-20 16:56


NVD link : CVE-2024-46943

Mitre link : CVE-2024-46943

CVE.ORG link : CVE-2024-46943


JSON object : View

Products Affected

opendaylight

  • authentication\,_authorization_and_accounting
CWE
NVD-CWE-noinfo CWE-520

.NET Misconfiguration: Use of Impersonation