What the vulnerability does

01Description

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.

Key dates

02Disclosure timeline

March 16, 2018 CVE published
August 5, 2024 Record updated