CVE-2017-1000406: High severity opendaylight vulnerability
Published Nov 30, 2017
·Updated
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
Affected Software
2 affected components
maven/org.opendaylight.integration:distribution-karaf<=0.6.4-Carbon
Opendaylight Karaf=0.6.1-carbon
Event History
Nov 30, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 17, 2022
Advisory Published
12:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-1000406?
CVE-2017-1000406 is considered to have a medium severity due to the risk of unauthorized access with the old password.
2
How do I fix CVE-2017-1000406?
To fix CVE-2017-1000406, manually clear the Karaf cache by restarting the service after a password change.
3
What versions of OpenDaylight Karaf are affected by CVE-2017-1000406?
CVE-2017-1000406 affects OpenDaylight Karaf versions up to and including 0.6.4-Carbon.
4
Is the old password exposed in CVE-2017-1000406 until cleared?
Yes, the old password can be used until the Karaf cache is manually cleared after a password change.
5
What is the nature of the vulnerability in CVE-2017-1000406?
The vulnerability in CVE-2017-1000406 is a cache management issue that fails to update the user's password in the system.