Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
References
| Link | Resource |
|---|---|
| https://github.com/floodlight/floodlight | Product |
| https://github.com/floodlight/floodlight/issues/870 | Exploit Issue Tracking |
| https://ieeexplore.ieee.org/document/10246976 | Technical Description |
Configurations
History
No history.
Information
Published : 2024-11-01 14:15
Updated : 2025-06-11 14:15
NVD link : CVE-2024-51406
Mitre link : CVE-2024-51406
CVE.ORG link : CVE-2024-51406
JSON object : View
Products Affected
projectfloodlight
- open_sdn_controller
CWE
CWE-290
Authentication Bypass by Spoofing
