Junglewise Threat Intelligence

CVE-2015-1778: OpenDaylight authentication bypass in karaf-tomcat realm

CVE-2015-1778 · Severity: critical · CVSS 9.8 · Published 2022-05-17

Vendors: Maven.

Executive brief

OpenDaylight, an open-source networking platform, contains a critical flaw where the system fails to verify login credentials. This allows any user to gain full administrative access by entering any username and password combination. An attacker could use this to take complete control of the networking infrastructure, potentially leading to data theft or service disruption.

Technical details

A vulnerability in the custom authentication realm used by the karaf-tomcat 'opendaylight' component in OpenDaylight allows for complete authentication bypass. The root cause is an improper implementation of the authentication logic (CWE-287) that fails to validate the provided credentials against a backend store, effectively accepting any input as valid. This is exploitable over the network without any prior privileges or user interaction. Successful exploitation grants the attacker the identity and permissions associated with the requested account, typically leading to full system compromise. The issue is resolved in version 0.2.3-Helium-SR3.

Affected products

  • OpenDaylight opendaylight-karaf-resources < 0.2.3-Helium-SR3

Timeline

  • 2015-03-20: disclosed: Initial disclosure on OSS-security mailing list
  • 2017-06-27: advisory: NVD published the CVE record
  • 2022-05-17: advisory: GitHub Advisory Database entry published

References