Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://github.com/floodlight/floodlight | Product |
| https://github.com/floodlight/floodlight/issues/870 | Exploit Issue Tracking |
| https://ieeexplore.ieee.org/document/10246976 | Technical Description |
Configurations
History
11 Jun 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-290 | |
| CPE | cpe:2.3:a:projectfloodlight:open_sdn_controller:1.2:*:*:*:*:*:*:* | |
| First Time |
Projectfloodlight open Sdn Controller
Projectfloodlight |
|
| References | () https://ieeexplore.ieee.org/document/10246976 - Technical Description | |
| References | () https://github.com/floodlight/floodlight/issues/870 - Exploit, Issue Tracking | |
| References | () https://github.com/floodlight/floodlight - Product |
01 Nov 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-11-01 14:15
Updated : 2025-06-11 14:15
NVD link : CVE-2024-51406
Mitre link : CVE-2024-51406
JSON object : View
Products Affected
projectfloodlight
- open_sdn_controller
CWE
CWE-290
Authentication Bypass by Spoofing
