Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/floodlight/floodlight | Product | 
| https://github.com/floodlight/floodlight/issues/870 | Exploit Issue Tracking | 
| https://ieeexplore.ieee.org/document/10246976 | Technical Description | 
Configurations
                    History
                    11 Jun 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:projectfloodlight:open_sdn_controller:1.2:*:*:*:*:*:*:* | |
| First Time | Projectfloodlight Projectfloodlight open Sdn Controller | |
| CWE | CWE-290 | |
| References | () https://github.com/floodlight/floodlight - Product | |
| References | () https://github.com/floodlight/floodlight/issues/870 - Exploit, Issue Tracking | |
| References | () https://ieeexplore.ieee.org/document/10246976 - Technical Description | 
04 Nov 2024, 19:35
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.2 | 
01 Nov 2024, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-11-01 14:15
Updated : 2025-06-11 14:15
NVD link : CVE-2024-51406
Mitre link : CVE-2024-51406
CVE.ORG link : CVE-2024-51406
JSON object : View
Products Affected
                projectfloodlight
- open_sdn_controller
CWE
                
                    
                        
                        CWE-290
                        
            Authentication Bypass by Spoofing
