Input validation error in OpenFlow - CVE-2018-1078
Published: March 16, 2018 / Updated: August 8, 2020
OpenFlow
Open Networking Foundation
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.