CVE-2008-2476
Summary
| CVE | CVE-2008-2476 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-03 15:07:10 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB). |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Force10 | Ftos | All | All | All | All |
| Operating System | Freebsd | Freebsd | 6.3 | All | All | All |
| Operating System | Freebsd | Freebsd | 7.1 | All | All | All |
| Operating System | Juniper | Jnos | All | All | All | All |
| Operating System | Netbsd | Netbsd | All | All | All | All |
| Operating System | Openbsd | Openbsd | 4.2 | All | All | All |
| Operating System | Openbsd | Openbsd | 4.3 | All | All | All |
| Operating System | Windriver | Vxworks | 5 | All | All | All |
| Operating System | Windriver | Vxworks | 5.5 | All | All | All |
| Operating System | Windriver | Vxworks | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| US-CERT Vulnerability Note VU#472363 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Force10 FTOS Routers IPv6 Neighbor Discovery Protocol Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| OpenBSD IPv6 Neighbor Discovery Protocol Neighbor Solicitation Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| OpenBSD IPv6 Neighbor Discovery Protocol Spoofing Bug Lets Remote Users Modify Routing Data in Certain Cases - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityTracker.com Archives - FreeBSD IPv6 Neighbor Discovery Protocol Spoofing Bug Lets Remote Users Modify Routing Data in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| security.freebsd.org/advisories/FreeBSD-SA-08:10.nd6.asc | af854a3a-2127-422b-91ae-364da2661108 | security.freebsd.org | Vendor Advisory |
| OpenBSD 4.3 errata | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| NetBSD IPv6 Neighbor Discovery Protocol Spoofing Bug Lets Remote Users Modify Routing Data in Certain Cases - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Juniper Networks | af854a3a-2127-422b-91ae-364da2661108 | www.juniper.net | |
| Juniper Products Neighbor Discovery Protocol Neighbor Solicitation Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Force10 Networks, Inc. Information for VU#472363 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| FreeBSD IPv6 Neighbor Discovery Protocol Neighbor Solicitation Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| NetBSD IPv6 Neighbor Discovery Protocol Neighbor Solicitation Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Wind River Systems, Inc. Information for VU#472363 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| OpenBSD 4.2 errata | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | |
| Multiple Vendors IPv6 Neighbor Discovery Protocol Implementation Address Spoofing Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-013.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | |
| About the security content of Time Capsule and AirPort Base Station (802.11n*) Firmware 7.4.1 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2017-09-28 | Joshua Bressers | Not vulnerable. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 2.1, 3, 4, 5 or Red Hat Enterprise MRG. |
There are currently no legacy QID mappings associated with this CVE.