<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 20:32:16 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[OPNFLWPLUG-361] [SECURITY] Topology spoofing via LLDP</title>
                <link>https://jira.opendaylight.org/browse/OPNFLWPLUG-361</link>
                <project id="10155" key="OPNFLWPLUG">OpenFlowPlugin</project>
                    <description>&lt;p&gt;It has been reported that it is possible for an attacker to spoof network topology via LLDP. Details are in this paper:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.internetsociety.org/sites/default/files/10_4_2.pdf&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://www.internetsociety.org/sites/default/files/10_4_2.pdf&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Two fixes are proposed:&lt;/p&gt;

&lt;p&gt;1) Implement nonces for the LLDP messages, although this leaves a problem with MITM attacks where a host can copy LLDP from one point in the topology to other point. That would create a fake link between two OpenFlow switches.&lt;/p&gt;

&lt;p&gt;2) Implement a mechanism that somehow warns administrator about unexpected topology changes.&lt;/p&gt;

&lt;p&gt;MITRE has been contacted requesting a CVE name for this issue.&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="27629">OPNFLWPLUG-361</key>
            <summary>[SECURITY] Topology spoofing via LLDP</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10000">Done</resolution>
                                        <assignee username="jgloncak">Jozef Gloncak</assignee>
                                    <reporter username="djorm@iix.net">David Jorm</reporter>
                        <labels>
                    </labels>
                <created>Mon, 16 Feb 2015 00:51:27 +0000</created>
                <updated>Mon, 27 Sep 2021 09:01:25 +0000</updated>
                            <resolved>Wed, 3 Jun 2015 08:48:23 +0000</resolved>
                                                                    <component>General</component>
                        <due>Mon, 16 Mar 2015 00:00:00 +0000</due>
                            <votes>0</votes>
                                    <watches>8</watches>
                                                                                                                <comments>
                            <comment id="56501" author="abhijit2511" created="Mon, 16 Feb 2015 01:27:31 +0000"  >&lt;p&gt;Michal,&lt;/p&gt;

&lt;p&gt;Can you look into this? I will catch up with you over IRC sometime. There is also a security advisory on this:&lt;br/&gt;
&lt;a href=&quot;https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-TBD_openflowplugin:_topology_spoofing_via_LLDP&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-TBD_openflowplugin:_topology_spoofing_via_LLDP&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Thanks,&lt;br/&gt;
Abhijit&lt;/p&gt;</comment>
                            <comment id="56502" author="djorm@iix.net" created="Thu, 19 Feb 2015 22:40:35 +0000"  >&lt;p&gt;CVE-2015-1611 and CVE-2015-1612 have been assigned to this issue. On the TSC list it has been suggested that an SR3 release is shipped on 3/30. Would it be possible to include a fix for this issue in SR3?&lt;/p&gt;</comment>
                            <comment id="56503" author="mirehak@cisco.com" created="Mon, 16 Mar 2015 18:49:23 +0000"  >&lt;p&gt;&lt;a href=&quot;https://git.opendaylight.org/gerrit/#/c/16193/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org/gerrit/#/c/16193/&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="56504" author="vishnoianil@gmail.com" created="Mon, 16 Mar 2015 19:52:13 +0000"  >&lt;p&gt;Above patch did not contain JUnit test, but we merged it because today is SR3 cut off date and we don&apos;t have enough time to add junit tests. Please keep this bug open till we include the junit tests.&lt;/p&gt;</comment>
                            <comment id="56505" author="mirehak@cisco.com" created="Mon, 16 Mar 2015 20:44:10 +0000"  >&lt;p&gt;merged&lt;/p&gt;</comment>
                            <comment id="56506" author="mirehak@cisco.com" created="Mon, 16 Mar 2015 23:03:43 +0000"  >&lt;p&gt;&lt;a href=&quot;https://git.opendaylight.org/gerrit/#/c/16208&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org/gerrit/#/c/16208&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="56507" author="david.jorm@gmail.com" created="Tue, 17 Mar 2015 04:44:55 +0000"  >&lt;p&gt;I have updated the security advisories page to reflect the availability of a patch commit: &lt;a href=&quot;https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-2015-1611_CVE-2015-1612_openflowplugin:_topology_spoofing_via_LLDP&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-2015-1611_CVE-2015-1612_openflowplugin:_topology_spoofing_via_LLDP&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Do we also need a patch for master to ensure this issue remains fixed in Lithium?&lt;/p&gt;</comment>
                            <comment id="56508" author="mirehak@cisco.com" created="Tue, 17 Mar 2015 05:52:29 +0000"  >&lt;p&gt;merged&lt;/p&gt;</comment>
                            <comment id="56509" author="mirehak@cisco.com" created="Tue, 17 Mar 2015 05:55:25 +0000"  >&lt;p&gt;(In reply to David Jorm from comment #7)&lt;br/&gt;
&amp;gt; I have updated the security advisories page to reflect the availability of a&lt;br/&gt;
&amp;gt; patch commit:&lt;br/&gt;
&amp;gt; &lt;a href=&quot;https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://wiki.opendaylight.org/view/Security_Advisories#.5BModerate.5D_CVE-&lt;/a&gt;&lt;br/&gt;
&amp;gt; 2015-1611_CVE-2015-1612_openflowplugin:_topology_spoofing_via_LLDP&lt;br/&gt;
&amp;gt; &lt;br/&gt;
&amp;gt; Do we also need a patch for master to ensure this issue remains fixed in&lt;br/&gt;
&amp;gt; Lithium?&lt;/p&gt;

&lt;p&gt;Yes,&lt;br/&gt;
we need to cherrypick &lt;a href=&quot;https://jira.opendaylight.org/browse/CONTROLLER-1196&quot; title=&quot;Impossible to add more than one TLVs with type 127&quot; class=&quot;issue-link&quot; data-issue-key=&quot;CONTROLLER-1196&quot;&gt;&lt;del&gt;CONTROLLER-1196&lt;/del&gt;&lt;/a&gt; and this one into master in order to have the same functionality in lithium.&lt;/p&gt;</comment>
                            <comment id="56510" author="jgloncak" created="Wed, 3 Jun 2015 08:48:05 +0000"  >&lt;p&gt;openflowplugin&lt;br/&gt;
==============&lt;br/&gt;
Merged on stable/lithium, stable/helium, master&lt;br/&gt;
Change-Id: I234305e827817aef2dcec820869bddca91fc2b33 - LLDPSpeaker&lt;br/&gt;
Change-Id: Ic8f50c88e7d8e3722d8d83a01ffa94a96bde313f - hash check in topology-discovery&lt;/p&gt;

&lt;p&gt;controller&lt;br/&gt;
==========&lt;br/&gt;
Merged on stable/lithium, stable/helium, master&lt;br/&gt;
Change-Id: I5d0c6b9a9e29213d3f25aa99ff7edd5b30e6c7a8 - LLDP refactor&lt;br/&gt;
Change-Id: Ifa1cab17206e1be37022bc8b49f7990649cbd356 - problem to add second TLV with type 127. (for stable/lithium was changed to squashing commit which contained changes for all changes necessary in controller. The reason was that &amp;gt;LLDP refactor&amp;lt; was merged in controller before &amp;gt;LLDP TLV support and testing&amp;lt; and &amp;gt;problem to add second TLV&amp;lt;&lt;/p&gt;

&lt;p&gt;Merged on: stable/helium, master&lt;br/&gt;
Change-Id: I56c807b46d889266fc43cdc9b35d00bf17bb4d09 - LLDP TLV support and testing&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10000">
                    <name>Blocks</name>
                                                                <inwardlinks description="is blocked by">
                                        <issuelink>
            <issuekey id="25750">CONTROLLER-1196</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>2723</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=2723]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10204" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>ODL SR Target Milestone</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10385"><![CDATA[Helium-3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                    <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i030of:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>