Impact
Floodlight commit 71fe8a7 permits an attacker to interfere with host communication by spoofing a network link; the attack exploits a misclassification of a port as non-boundary, which leads to incorrect routing or forwarding of traffic through that port. The flaw is an example of a denial of service vulnerability under CWE-669.
Affected Systems
The product affected is Floodlight (projectfloodlight:Floodlight). No explicit version range is provided beyond the mention of commit 71fe8a7, indicating that versions including that commit are vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 3 indicates a low overall severity, and the EPSS score is below 1%. The vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. The likely attack vector is network‑based: an adversary capable of injecting frames or manipulating the link can trigger the misclassification without requiring local user privileges on the Floodlight controller. The threat primarily results in service disruption rather than confidentiality or integrity compromise.
OpenCVE Enrichment