« Volver al listado

CVE-2018-1078

Estado: ModificadaCrítica (9.8)—

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-1078",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "OpenDayLight",
          "product": "OpenDayLight",
          "versions": [
            {
              "status": "affected",
              "version": "Carbon SR3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-03-16T20:29:00.383",
  "references": [
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1533501",
      "tags": [
        "Issue Tracking",
        "Not Applicable"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://jira.opendaylight.org/browse/OPNFLWPLUG-971",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1533501",
      "tags": [
        "Issue Tracking",
        "Not Applicable"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jira.opendaylight.org/browse/OPNFLWPLUG-971",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired."
    },
    {
      "lang": "es",
      "value": "OpenDayLight, en versiones Carbon SR3 y anteriores, contiene una vulnerabilidad durante la reconciliación de nodos que puede resultar en flujos de tráfico que deberían estar caducados o deberían hacerlo en breves se reinstalen y resulten en la permisión de tráfico que debería estar caducado."
    }
  ],
  "lastModified": "2026-06-17T01:50:25.867",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opendaylight:openflow:*:*:*:*:*:opendaylight:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4A8BF0D-789C-4D5D-B8CF-662DCA292260",
              "versionEndIncluding": "carbon"
            },
            {
              "criteria": "cpe:2.3:a:opendaylight:openflow:sp1:*:*:*:*:opendaylight:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC3015BD-500C-4D8A-9C09-177C9D088F15"
            },
            {
              "criteria": "cpe:2.3:a:opendaylight:openflow:sp2:*:*:*:*:opendaylight:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5E2B666-81F4-4030-B717-775B6C96AE68"
            },
            {
              "criteria": "cpe:2.3:a:opendaylight:openflow:sp3:*:*:*:*:opendaylight:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25C9A05F-EBD0-416E-9EA5-89C4292BCA24"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}