dl.acm.org
https://dl.acm.org/doi/10.1145/3658644.3690345 CVE-2024-37018
CRITICAL
Record summary
CVE-2024-37018 has a selected CVSS score of 9.1 (critical).
Description
The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
opendaylightBrowse linuxfoundation / opendaylightDefault status: unknown | CVE List | 0.15.3 | affected |
References
6github.com
https://github.com/mzc796/marionette_odl github.com
https://github.com/mzc796/marionette_onos jira.opendaylight.org
https://jira.opendaylight.org/browse/DISCOVERY-2 mvnrepository.com
https://mvnrepository.com/artifact/org.opendaylight.controller nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-37018