{"id":"GHSA-49wf-927p-jpvj","summary":"OpenFlow plugin for OpenDaylight allows spoofing the SDN topology","details":"OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to \"fake LLDP injection.\"","aliases":["CVE-2015-1611"],"modified":"2025-04-22T17:57:19.102798Z","published":"2022-05-17T02:50:39Z","database_specific":{"github_reviewed_at":"2025-04-22T17:32:26Z","nvd_published_at":"2017-04-04T17:59:00Z","cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1611"},{"type":"WEB","url":"https://git.opendaylight.org/gerrit/#/c/16193"},{"type":"WEB","url":"https://git.opendaylight.org/gerrit/#/c/16208"},{"type":"PACKAGE","url":"https://github.com/opendaylight/openflowplugin"},{"type":"WEB","url":"https://web.archive.org/web/20150510044305/https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-2015-1611_CVE-2015-1612_openflowplugin:_topology_spoofing_via_LLDP"},{"type":"WEB","url":"https://web.archive.org/web/20150701104709/https://www.internetsociety.org/sites/default/files/10_4_2.pdf"}],"affected":[{"package":{"name":"org.opendaylight.openflowplugin:openflowplugin","ecosystem":"Maven","purl":"pkg:maven/org.opendaylight.openflowplugin/openflowplugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.6-Helium-SR3"}]}],"versions":["0.0.1","0.0.2","0.0.3-Helium","0.0.4-Helium-SR1","0.0.4-Helium-SR1.1","0.0.5-Helium-SR2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-49wf-927p-jpvj/GHSA-49wf-927p-jpvj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}