PT-2019-7085 · Open Floodlight · Open Floodlight Sdn Controller
Publicado
2019-10-23
·
Atualizado
2019-10-30
·
CVE-2014-2304
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Open Floodlight SDN controller software version 0.90
Description
A flaw in OpenFlow protocol processing could result in a denial of service attack and crashing of the controller service. This is caused by specific malformed and mistimed FEATURES REPLY messages, which prevent the controller service from deleting switch and port data from its internal tracking structures.
Recommendations
For version 0.90, consider disabling the OpenFlow protocol processing until a patch is available to prevent exploitation of the flaw. Restrict access to the controller service to minimize the risk of a denial of service attack. Avoid using malformed and mistimed FEATURES REPLY messages in the affected OpenFlow protocol processing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Open Floodlight Sdn Controller