Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities

BID:1010

Info

Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities

Bugtraq ID: 1010
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: Feb 25 2000 12:00AM
Updated: Feb 25 2000 12:00AM
Credit: The first 4 vulnerabilities were posted to the Bugtraq mailing list by Swift Griggs <[email protected]> on February 25, 2000. The second 3 were sent by Mike Wade <[email protected]> to the Bugtraq mailing list on February 25, 2000.
Vulnerable: Nortel Networks Netgear ISDN 348.0 RH
Nortel Networks Netgear ISDN 328.0 RT
Not Vulnerable:

Discussion

Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities

A number of vulnerabilities exist in the Netgear ISDN RH348 and RT328 routers, made by Nortel networks. These vulnerabilities can result in the denial of traffic flowing through the router, as well as prevent effective management of the router.

Denial of Service 1: It has been reported that SYN scanning the router, using a tool like NMAP, will render telnet connectivity to these routers nonexistent.

Denial of Service 2: Establishing a telnet connection to the router will prevent any other connections from taking place, regardless of whether or not the connecting user has authenticated.

Denial of Service 3: Sending a flood of ICMP redirects will cause the router to stop routing packets. It will take approximately 30 seconds for the router to recover, once the flood has stopped.

Denial of Service 4: The router will accept and apply RIP packets originating on both interfaces. This allows an attacker to cause packets to no longer route correctly, or possibly route traffic through another machine.

Denial of Service 5: Sending a single UDP packet of between 63000 and 65000 bytes will cause the router to stop routing packets for up to 30 seconds.

Denial of Service 6: Certain types of legitimate traffic behave poorly when running NAT. These services include things like IRC DCC and Real Audio/Video.

Denial of Service 7: Traffic is often dropped in NAT mode when the router has been connected for over 12 hours. Active connections will not be dropped, but new connections can not be established.

Exploit / POC

Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities

Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

The Netgear routers can have ACL's applied to them. Applying ACL's to deny access to all ports on the router, except those explicitly allowed will help remove some of these problems. It should also be possible to disable RIP.

References

Nortel Netgear ISDN RH348 and RT328 Denial Of Service Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report