Vulnerability Details CVE-2024-46943
An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, even if this rogue controller does not possess the complete cluster configuration information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.5%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-46943
-
_authorization_and_accounting:-
-
_authorization_and_accounting:0.17.15
-
_authorization_and_accounting:0.18.5
-
_authorization_and_accounting:0.19.0
-
_authorization_and_accounting:0.19.1
-
_authorization_and_accounting:0.19.2
-
_authorization_and_accounting:0.19.3
-
cpe:2.3:a:opendaylight:authentication