Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opendaylight

First CVE: Aug 26, 2014Active for: 12 yearsTotal CVEs: 17
31.0
VTI Score
Low

Opendaylight is a Software-Defined Networking (SDN) controller platform that occupies a prominent niche in network infrastructure, with its vulnerabilities concentrating across the core controller, OpenFlow components, and authentication and access-control subsystems. The vendor's exposure skews toward serious outcomes, with a meaningful share reaching critical severity, and recurs through weakness classes including improper input validation, NULL-pointer dereferences, and uncontrolled resource consumption that reflect the parsing and state-management demands of network protocol handling. Current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Opendaylight over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2014
11 years ago
Most Recent CVE
Sep 15, 2024
677 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1132CRITICAL
A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. S
Jun 20, 20189.830NONO
CVE-2018-1078CRITICAL
OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly bein
Mar 16, 20189.829NONO
CVE-2015-1778CRITICAL
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
Jun 27, 20179.825NONO
CVE-2017-1000361HIGH
DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight
Apr 24, 20177.525NONO
CVE-2017-1000357HIGH
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the featur
Apr 24, 20177.525NONO
CVE-2017-1000411HIGH
OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of
Jan 31, 20187.524NONO
CVE-2017-1000406HIGH
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
Nov 30, 20177.524NONO
CVE-2017-1000358MEDIUM
Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: Ope
Apr 24, 20176.523NONO
CVE-2024-46943HIGH
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, eve
Sep 15, 20247.522NONO
CVE-2024-46942MEDIUM
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deploymen
Sep 15, 20246.522NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
35%
47%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (94.1%)
Unknown1 (5.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High0 (0.0%)
Unknown1 (5.9%)
User Interaction
None16 (94.1%)
Unknown1 (5.9%)
Required0 (0.0%)
Privileges Required
Low3 (17.6%)
High0 (0.0%)
None13 (76.5%)
Unknown1 (5.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opendaylight.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opendaylight — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opendaylight's Products

View all 2 CNAs →

Top CWEs