Input Validation Vulnerability in Floodlight Vendor's StaticFlowEntryPusherResource Java Component
CVE-2020-18683
9.8CRITICAL
Summary
Floodlight, version 1.2, contains a significant input validation flaw within the StaticFlowEntryPusherResource.java component. This vulnerability arises from the mishandling of undefined fields in the checkFlow method. An attacker could exploit this weakness to manipulate the system's behavior leading to unintended effects on network management functionalities.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved