An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
References
Link | Resource |
---|---|
https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html | Release Notes |
https://doi.org/10.48550/arXiv.2408.16940 | Technical Description |
https://lf-opendaylight.atlassian.net/browse/AAA-285 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
14 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-520 |
Information
Published : 2024-09-15 23:15
Updated : 2025-03-14 19:15
NVD link : CVE-2024-46943
Mitre link : CVE-2024-46943
CVE.ORG link : CVE-2024-46943
JSON object : View
Products Affected
opendaylight
- authentication\,_authorization_and_accounting
CWE