CVE-2020-18685

CRITICAL

Floodlight < 1.2 - Improper Input Validation in StaticFlowEntryPusherResource

Title source: llm
STIX 2.1

Description

Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://drive.google.com/open?id=1oIt6jViGxLALUkLVELsQpC26MJYFZt2U

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 63.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
atlassian/floodlight < 1.2
Published Sep 30, 2021
Tracked Since Feb 18, 2026