CVE-2024-46943

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/09/2024
Last modified:
14/03/2025

Description

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opendaylight:authentication\,_authorization_and_accounting:*:*:*:*:*:*:*:* 0.19.3 (including)