CVE-2024-46943

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opendaylight:authentication\,_authorization_and_accounting:*:*:*:*:*:*:*:*

History

14 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-520

Information

Published : 2024-09-15 23:15

Updated : 2025-03-14 19:15


NVD link : CVE-2024-46943

Mitre link : CVE-2024-46943

CVE.ORG link : CVE-2024-46943


JSON object : View

Products Affected

opendaylight

  • authentication\,_authorization_and_accounting
CWE
NVD-CWE-noinfo CWE-520

.NET Misconfiguration: Use of Impersonation