CVE-2024-51406

Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
Configurations

Configuration 1 (hide)

cpe:2.3:a:projectfloodlight:open_sdn_controller:1.2:*:*:*:*:*:*:*

History

11 Jun 2025, 14:15

Type Values Removed Values Added
References () https://github.com/floodlight/floodlight - () https://github.com/floodlight/floodlight - Product
References () https://github.com/floodlight/floodlight/issues/870 - () https://github.com/floodlight/floodlight/issues/870 - Exploit, Issue Tracking
References () https://ieeexplore.ieee.org/document/10246976 - () https://ieeexplore.ieee.org/document/10246976 - Technical Description
CPE cpe:2.3:a:projectfloodlight:open_sdn_controller:1.2:*:*:*:*:*:*:*
First Time Projectfloodlight open Sdn Controller
Projectfloodlight
CWE CWE-290

04 Nov 2024, 19:35

Type Values Removed Values Added
Summary
  • (es) Floodlight SDN Open Flow Controller v.1.2 tiene un problema que permite que los hosts locales creen paquetes LLDP falsos que hacen que Floodlight no detecte clústeres específicos, lo que a su vez genera que no se detecten hosts dentro y fuera del clúster.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2

01 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-01 14:15

Updated : 2025-06-11 14:15


NVD link : CVE-2024-51406

Mitre link : CVE-2024-51406

CVE.ORG link : CVE-2024-51406


JSON object : View

Products Affected

projectfloodlight

  • open_sdn_controller
CWE
CWE-290

Authentication Bypass by Spoofing