Back

CRITICAL

openflow: Denial of Service, Improper Authentication and Authorization, and Covert Channel in the OpenFlow handshake

Published May 24, 2018

Description

OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the controller. that can result in Denial of Service, Unauthorized Access, Network Instability. This attack appear to be exploitable via Network connectivity: the attacker must first establish a transport connection with the OpenFlow controller and then initiate the OpenFlow handshake.

Affected products

Remediation

Red Hat mitigation

Enable TLS in OpenFlow plugin. Upstream documentation is a useful resource. https://wiki.opendaylight.org/view/OpenDaylight_OpenFlow_Plugin:_TLS_Support

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 24, 2018
Updated Aug 5, 2024
Reserved Apr 3, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 9, 2018
ENISA EUVD
Assigner mitre
Published May 24, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-1861