Vulnerability CVE-2024-46943


Published: 2024-09-15   Modified: 2024-09-16

Description:
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.

 References:
https://doi.org/10.48550/arXiv.2408.16940
https://lf-opendaylight.atlassian.net/browse/AAA-285
https://docs.opendaylight.org/en/latest/release-notes/projects/aaa.html

Copyright 2024, cxsecurity.com

 

Back to Top