Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
History

Wed, 11 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Projectfloodlight open Sdn Controller
Weaknesses CWE-290
CPEs cpe:2.3:a:projectfloodlight:open_sdn_controller:1.2:*:*:*:*:*:*:*
Vendors & Products Projectfloodlight open Sdn Controller

Mon, 04 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Projectfloodlight
Projectfloodlight floodlight
CPEs cpe:2.3:a:projectfloodlight:floodlight:1.2:*:*:*:*:*:*:*
Vendors & Products Projectfloodlight
Projectfloodlight floodlight
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 Nov 2024 13:45:00 +0000

Type Values Removed Values Added
Description Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-01T00:00:00

Updated: 2024-11-04T19:11:07.872Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-51406

cve-icon Vulnrichment

Updated: 2024-11-04T19:11:03.386Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-01T14:15:07.073

Modified: 2025-06-11T14:15:56.927

Link: CVE-2024-51406

cve-icon Redhat

No data.