Projectfloodlight develops a narrowly scoped software-defined networking controller product that sits in the management plane of network infrastructure, presenting a focused attack surface centered on the Floodlight OpenFlow controller and related SDN control applications. The vulnerability profile reflects the input-handling and resource-management demands of a network control plane: recurring weakness classes include improper input validation, uncontrolled resource consumption, authentication bypass through spoofing, and cross-site scripting, patterns that are typical for web-facing management interfaces. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Projectfloodlight over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7333HIGH A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individ | Oct 23, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-1000163MEDIUM Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack ap | Apr 18, 2018 | 6.1 | 20 | NO | NO |
CVE-2014-2304HIGH A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the controller service. This effect is the | Oct 23, 2019 | 7.5 | 19 | NO | NO |
CVE-2024-51407MEDIUM Floodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false broadcast ports causing inter-host communication anomalies. | Nov 1, 2024 | 6.2 | 18 | NO | NO |
CVE-2024-51406MEDIUM Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn lea | Nov 1, 2024 | 6.2 | 18 | NO | NO |
CVE-2024-29461MEDIUM An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component. | Apr 12, 2024 | 6.3 | 18 | NO | NO |
CVE-2024-57673MEDIUM An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module | Feb 6, 2025 | 5.5 | 17 | NO | NO |
CVE-2024-57672MEDIUM An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing module. | Feb 6, 2025 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Projectfloodlight.
Media articles that mention a CVE ID that affects a product developed by Projectfloodlight — matched by CVE ID, not by vendor name.