CRITICAL🇵🇱 Wersja polska

CVE-2024-37018

CVSS 9.1v3.1pub. 2024-05-31upd. 2026-04-15

The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

🤖 AI Analysis
How it works

An application connected to the OpenDaylight controller can manipulate the path that discovery packets take to detect network topology using API requests. By controlling the route of these packets, an attacker is able to inject false information about the network topology into the SDN controller. As a result, the controller builds an incorrect picture of the network, which can then be exploited to redirect traffic or hide actual connections.

Impact

An attacker can gain unauthorized access to sensitive network topology information (breach of confidentiality) and manipulate the routing tables and forwarding decisions of the SDN controller (breach of integrity), which may lead to interception or redirection of network traffic.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references. It is recommended to monitor the DISCOVERY-2 issue in the OpenDaylight project Jira system to track the progress of the fix. Additionally, access to the controller API should be restricted only to trusted applications and network segments.

Who is affected

OpenDaylight version 0.15.3 (SDN controller)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References