CVE-2024-37018: Critical severity Opendaylight OpenDaylight Controller vulnerability
Published May 31, 2024
·Updated
The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.
Affected Software
1 affected component
Opendaylight OpenDaylight Controller
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 31, 2024
CVE Published
via NVD·01:15 AM
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Dec 16, 2024
Data Sourced
via MITRE·09:10 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-37018?
CVE-2024-37018 has a high severity rating as it allows potential topology poisoning in the OpenDaylight controller.
2
How do I fix CVE-2024-37018?
To fix CVE-2024-37018, update your OpenDaylight controller to the latest version that mitigates this vulnerability.
3
What kind of attacks can CVE-2024-37018 facilitate?
CVE-2024-37018 can facilitate topology poisoning attacks through API requests, compromising network discovery.
4
Is my OpenDaylight controller vulnerable to CVE-2024-37018?
If you are using OpenDaylight version 0.15.3, your controller is vulnerable to CVE-2024-37018.
5
What should I do if I am impacted by CVE-2024-37018?
If impacted by CVE-2024-37018, immediately update your OpenDaylight controller and review your network for potential exploitation.