opendaylight: Port-Status packets sent to Controller create exceptions
Published Apr 24, 2017
7.5
HIGHCVSS 3.0
EPSS 1.40%
Description
DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.
Affected products
No data.
- 3.3
- 4.0
No data.
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
opendaylight
Will not fix
Red Hat OpenStack Platform 12 (Pike)
opendaylight
Will not fix
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects OpenDaylight in Red Hat OpenStack Platform 12.0 (Pike). However, OpenDaylight is only supported in segregated management networks; by default, at worst, this flaw would only be exposed on an admin network. For this reason, Red Hat Product Security has rated this issue as having security impact of Low. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (7)
- https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000361 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1447856 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3209 Advisory
- https://github.com/advisories/GHSA-8p5x-w9cv-92hv Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000361
- https://www.cve.org/CVERecord?id=CVE-2017-1000361
| Link | Providers | Tags |
|---|---|---|
| https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-1000361 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1447856 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3209 | Advisory | |
| https://github.com/advisories/GHSA-8p5x-w9cv-92hv | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000361 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000361 |
Change history (0)
No recorded changes yet.