Impact
The vulnerability is a directory traversal flaw in the cluster-admin:backup-datastore component of the OpenDaylight Controller version 12.0.5. It allows an attacker to craft a request that causes the component to resolve file paths outside the intended backup directory. The input does not specify the precise consequence of the traversal, so the impact is limited to the potential for unauthorized file access or modifying configuration files, as defined by CWE-22.
Affected Systems
The flaw is present in OpenDaylight Controller 12.0.5. No other affected versions are mentioned in the input.
Risk and Exploitability
The vulnerability has a CVSS score of 9.1 and an EPSS score of less than 1%, indicating a high severity but low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is a remote API request to the backup datastore endpoint; based on the description, it is inferred that no authentication requirement is explicitly stated, meaning the exploit could target both authenticated and unauthenticated requests depending on deployment configuration.
OpenCVE Enrichment