VulnerabilityAnalyzed
CVE-2024-51406
Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
MEDIUM 6.2EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
- CVSS 3.1
- 6.2 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- projectfloodlight/open sdn controller
- Source
- cve@mitre.org
References
- https://github.com/floodlight/floodlightProduct
- https://github.com/floodlight/floodlight/issues/870Exploit, Issue Tracking
- https://ieeexplore.ieee.org/document/10246976Technical Description
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.