Vulnerability Description
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opendaylight | Model-Driven Service Abstraction Layer | <= 13.0.1 |
Related Weaknesses (CWE)
References
- https://docs.opendaylight.org/en/latest/release-notes/projects/mdsal.htmlRelease Notes
- https://doi.org/10.48550/arXiv.2408.16940Technical Description
- https://lf-opendaylight.atlassian.net/browse/MDSAL-869Issue TrackingVendor Advisory
FAQ
What is CVE-2024-46942?
CVE-2024-46942 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.
How severe is CVE-2024-46942?
CVE-2024-46942 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-46942?
Check the references section above for vendor advisories and patch information. Affected products include: Opendaylight Model-Driven Service Abstraction Layer.