CVE-2024-37018

CRITICAL

OpenDaylight 0.15.3 - SSRF

Title source: llm
STIX 2.1

Description

The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

Scores

CVSS v3 9.1
EPSS 0.0025
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-648
Status published
Published May 31, 2024
Tracked Since Feb 18, 2026