CVE-2017-1000411 is a resource exhaustion vulnerability affecting OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, and Anil Vishnoi, specifically within its OpenFlow Plugin. The flaw allows an attacker to trigger a controller shutdown by sending multiple OpenFlow flows with timeouts, causing expired flow entries to persist in the CONFIG DATASTORE and consume excessive memory. The vulnerability has a CVSSv3 score of 7.5 (HIGH), indicating a severe impact. It can be exploited remotely with low attack complexity and no user interaction (AV:N/AC:L/PR:N/UI:N), leading to a complete denial of service (A:H) for the controller. Both north-bound and south-bound attacks are possible. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's Known Exploited Vulnerabilities catalog. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
boronCPE matchmatch criteria | cpe:2.3:a:opendaylight:opendaylight:boron:*:*:*:*:*:*:* | ||
carbonCPE matchmatch criteria | cpe:2.3:a:opendaylight:opendaylight:carbon:*:*:*:*:*:*:* | ||
nitrogenCPE matchmatch criteria | cpe:2.3:a:opendaylight:opendaylight:nitrogen:*:*:*:*:*:*:* | ||
boronCPE matchmatch criteria | cpe:2.3:a:opendaylight:openflow:boron:*:*:*:*:opendaylight:*:* | ||
carbonCPE matchmatch criteria | cpe:2.3:a:opendaylight:openflow:carbon:*:*:*:*:opendaylight:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.