Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
History

Mon, 04 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Projectfloodlight
Projectfloodlight floodlight
CPEs cpe:2.3:a:projectfloodlight:floodlight:1.2:*:*:*:*:*:*:*
Vendors & Products Projectfloodlight
Projectfloodlight floodlight
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 Nov 2024 13:45:00 +0000

Type Values Removed Values Added
Description Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-01T00:00:00

Updated: 2024-11-04T19:11:07.872Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-51406

cve-icon Vulnrichment

Updated: 2024-11-04T19:11:03.386Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-01T14:15:07.073

Modified: 2024-11-04T19:35:17.410

Link: CVE-2024-51406

cve-icon Redhat

No data.