An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
References
Link | Resource |
---|---|
https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html | Release Notes |
https://doi.org/10.48550/arXiv.2408.16940 | Technical Description |
https://lf-opendaylight.atlassian.net/browse/AAA-285 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
24 Oct 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CWE |
20 Sep 2024, 16:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html - Release Notes | |
References | () https://doi.org/10.48550/arXiv.2408.16940 - Technical Description | |
References | () https://lf-opendaylight.atlassian.net/browse/AAA-285 - Issue Tracking, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:opendaylight:authentication\,_authorization_and_accounting:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
First Time |
Opendaylight authentication\, Authorization And Accounting
Opendaylight |
17 Sep 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-520 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
16 Sep 2024, 15:30
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Sep 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-15 23:15
Updated : 2024-10-24 17:35
NVD link : CVE-2024-46943
Mitre link : CVE-2024-46943
CVE.ORG link : CVE-2024-46943
JSON object : View
Products Affected
opendaylight
- authentication\,_authorization_and_accounting
CWE