CVE-2014-2304 describes a denial-of-service vulnerability in version 0.90 of the Open Floodlight SDN controller. This flaw, stemming from improper OpenFlow protocol processing of malformed FEATURES_REPLY messages, prevents the controller from correctly deleting switch and port data, ultimately leading to a service crash. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, allowing an unauthenticated attacker to cause a complete loss of availability for the controller. There is no evidence of active exploitation, nor is public exploit code available, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.90CPE matchmatch criteria | cpe:2.3:a:projectfloodlight:open_sdn_controller:0.90:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.