Opendaylight is a Software-Defined Networking (SDN) controller platform that occupies a prominent niche in network infrastructure, with its vulnerabilities concentrating across the core controller, OpenFlow components, and authentication and access-control subsystems. The vendor's exposure skews toward serious outcomes, with a meaningful share reaching critical severity, and recurs through weakness classes including improper input validation, NULL-pointer dereferences, and uncontrolled resource consumption that reflect the parsing and state-management demands of network protocol handling. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opendaylight over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1132CRITICAL A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. S | Jun 20, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-1078CRITICAL OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly bein | Mar 16, 2018 | 9.8 | 29 | NO | NO |
CVE-2015-1778CRITICAL The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination. | Jun 27, 2017 | 9.8 | 25 | NO | NO |
CVE-2017-1000361HIGH DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight | Apr 24, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-1000357HIGH Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the featur | Apr 24, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-1000411HIGH OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of | Jan 31, 2018 | 7.5 | 24 | NO | NO |
CVE-2017-1000406HIGH OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart). | Nov 30, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-1000358MEDIUM Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: Ope | Apr 24, 2017 | 6.5 | 23 | NO | NO |
CVE-2024-46943HIGH An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, eve | Sep 15, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-46942MEDIUM In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deploymen | Sep 15, 2024 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opendaylight.
Media articles that mention a CVE ID that affects a product developed by Opendaylight — matched by CVE ID, not by vendor name.