CVE-2017-1000406: Opendaylight Karaf

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).

Affected products

Published 2017-11-30. Last modified 2026-06-17.