CVE-2018-1078

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/03/2018
Last modified:
09/10/2019

Description

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opendaylight:openflow:*:*:*:*:*:opendaylight:*:* carbon (including)
cpe:2.3:a:opendaylight:openflow:sp1:*:*:*:*:opendaylight:*:*
cpe:2.3:a:opendaylight:openflow:sp2:*:*:*:*:opendaylight:*:*
cpe:2.3:a:opendaylight:openflow:sp3:*:*:*:*:opendaylight:*:*