CVE-2024-46943: Critical severity opendaylight authentication, authorization and accounting vulnerability
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46943?
CVE-2024-46943 is considered a critical vulnerability due to the potential for unauthorized access by rogue controllers.
How do I fix CVE-2024-46943?
To fix CVE-2024-46943, upgrade OpenDaylight Authentication, Authorization, and Accounting to versions later than 0.19.3.
What software is affected by CVE-2024-46943?
CVE-2024-46943 affects OpenDaylight Authentication, Authorization and Accounting versions up to 0.19.3.
What are the implications of CVE-2024-46943?
The implications of CVE-2024-46943 include the risk of a rogue controller impersonating offline peers in a cluster.
Can I exploit CVE-2024-46943?
Yes, if a rogue controller gains access to the cluster, it can exploit CVE-2024-46943 to impersonate other controllers.