PT-2024-25939 · Unknown · Faucet Sdn Ryu
Erodedelk
·
Published
2024-05-04
·
Updated
2024-07-03
·
CVE-2024-34489
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Faucet SDN Ryu version 4.34
Description
The issue allows attackers to cause a denial of service, resulting in an infinite loop, via a specific condition where
length=0. This is related to the OFPHello function in the parser.py file.Recommendations
For Faucet SDN Ryu version 4.34, consider disabling the
OFPHello function in parser.py to prevent the denial of service until a patch is available. Restrict access to the parser.py module to minimize the risk of exploitation. Avoid using the length=0 condition in the affected API endpoint until the issue is resolved.Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Faucet Sdn Ryu