PT-2019-7085 · Open Floodlight · Open Floodlight Sdn Controller

Published

2019-10-23

·

Updated

2019-10-30

·

CVE-2014-2304

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Open Floodlight SDN controller software version 0.90
Description A flaw in OpenFlow protocol processing could result in a denial of service attack and crashing of the controller service. This is caused by specific malformed and mistimed FEATURES REPLY messages, which prevent the controller service from deleting switch and port data from its internal tracking structures.
Recommendations For version 0.90, consider disabling the OpenFlow protocol processing until a patch is available to prevent exploitation of the flaw. Restrict access to the controller service to minimize the risk of a denial of service attack. Avoid using malformed and mistimed FEATURES REPLY messages in the affected OpenFlow protocol processing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2304

Affected Products

Open Floodlight Sdn Controller