CVE-2024-37018

CRITICAL

OpenDaylight 0.15.3 - Topology Poisoning via Discovery Packet Path Manipulation

Title source: llm
STIX 2.1

Description

The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

Scores

CVSS v3 9.1
EPSS 0.0043
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-648
Status published
Published May 31, 2024
Tracked Since Feb 18, 2026