Vulnerabilities > Opendaylight > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-06-20 CVE-2018-1132 SQL Injection vulnerability in Opendaylight Sdninterfaceapp
A flaw was found in Opendaylight's SDNInterfaceapp (SDNI).
network
low complexity
opendaylight CWE-89
critical
9.8
2018-03-16 CVE-2018-1078 Unspecified vulnerability in Opendaylight Openflow Sp1/Sp2/Sp3
OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.
network
low complexity
opendaylight
critical
9.8
2017-06-27 CVE-2015-1778 Improper Authentication vulnerability in Opendaylight
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
network
low complexity
opendaylight CWE-287
critical
9.8