Executive brief
OpenDaylight, an open-source networking platform, contains a critical flaw where the system fails to verify login credentials. This allows any user to gain full administrative access by entering any username and password combination. An attacker could use this to take complete control of the networking infrastructure, potentially leading to data theft or service disruption.
Technical details
A vulnerability in the custom authentication realm used by the karaf-tomcat 'opendaylight' component in OpenDaylight allows for complete authentication bypass. The root cause is an improper implementation of the authentication logic (CWE-287) that fails to validate the provided credentials against a backend store, effectively accepting any input as valid. This is exploitable over the network without any prior privileges or user interaction. Successful exploitation grants the attacker the identity and permissions associated with the requested account, typically leading to full system compromise. The issue is resolved in version 0.2.3-Helium-SR3.
Affected products
- OpenDaylight opendaylight-karaf-resources < 0.2.3-Helium-SR3
Timeline
- 2015-03-20: disclosed: Initial disclosure on OSS-security mailing list
- 2017-06-27: advisory: NVD published the CVE record
- 2022-05-17: advisory: GitHub Advisory Database entry published
References
- https://api.github.com/users/simon-reisinger-dynatrace
- https://github.com/simon-reisinger-dynatrace
- https://api.github.com/users/simon-reisinger-dynatrace/gists%7B/gist_id%7D
- https://api.github.com/users/simon-reisinger-dynatrace/repos
- https://avatars.githubusercontent.com/u/176280510?v=4
- https://api.github.com/users/simon-reisinger-dynatrace/events%7B/privacy%7D