Description
Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
Published: 2026-09-13
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Host Communication
Action: Apply Patch
AI Analysis

Impact

Floodlight commit 71fe8a7 permits an attacker to interfere with host communication by spoofing a network link; the attack exploits a misclassification of a port as non-boundary, which leads to incorrect routing or forwarding of traffic through that port. The flaw is an example of a denial of service vulnerability under CWE-669.

Affected Systems

The product affected is Floodlight (projectfloodlight:Floodlight). No explicit version range is provided beyond the mention of commit 71fe8a7, indicating that versions including that commit are vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 3 indicates a low overall severity, and the EPSS score is below 1%. The vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. The likely attack vector is network‑based: an adversary capable of injecting frames or manipulating the link can trigger the misclassification without requiring local user privileges on the Floodlight controller. The threat primarily results in service disruption rather than confidentiality or integrity compromise.

Generated by OpenCVE AI on September 15, 2026 at 18:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Floodlight to the latest release that includes the fix for link spoofing misclassification.
  • Verify and ports are correctly marked as boundaries.
  • Monitor network traffic between untrusted and trusted network segments.

Generated by OpenCVE AI on September 15, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Host Communication Disruption via Link Spoofing in Floodlight

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Host Communication Disruption via Link Spoofing in Floodlight

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Link Spoofing Causing Host Communication Disruption in Floodlight

Mon, 14 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Link Spoofing Causing Host Communication Disruption in Floodlight

Sun, 13 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Projectfloodlight
Projectfloodlight floodlight
Vendors & Products Projectfloodlight
Projectfloodlight floodlight

Sun, 13 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
Weaknesses CWE-669
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Projectfloodlight Floodlight
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:15:50.920Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-45480

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:53.381Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T19:16:52.553

Modified: 2026-09-22T20:00:03.713

Link: CVE-2025-45480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres