PT-2019-7085 · Open Floodlight · Open Floodlight Sdn Controller

Publicado

2019-10-23

·

Atualizado

2019-10-30

·

CVE-2014-2304

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Open Floodlight SDN controller software version 0.90
Description A flaw in OpenFlow protocol processing could result in a denial of service attack and crashing of the controller service. This is caused by specific malformed and mistimed FEATURES REPLY messages, which prevent the controller service from deleting switch and port data from its internal tracking structures.
Recommendations For version 0.90, consider disabling the OpenFlow protocol processing until a patch is available to prevent exploitation of the flaw. Restrict access to the controller service to minimize the risk of a denial of service attack. Avoid using malformed and mistimed FEATURES REPLY messages in the affected OpenFlow protocol processing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2304

Produtos afetados

Open Floodlight Sdn Controller