Enterasys XSR Security Router Record Route Denial Of Service Vulnerability
BID:10653
Info
Enterasys XSR Security Router Record Route Denial Of Service Vulnerability
| Bugtraq ID: | 10653 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0674 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2004 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | "Frederico Queiroz" <[email protected]> reported this vulerability. |
| Vulnerable: |
Enterasys XSR-3000 Enterasys XSR-1850 7.0 .0.0 Enterasys XSR-1805 7.0 .0.0 |
| Not Vulnerable: | |
Discussion
Enterasys XSR Security Router Record Route Denial Of Service Vulnerability
Enterasys XSR Security Routers are reported prone to a denial of service vulnerability.
When these devices pass packets with the IP record route option, they will reportedly crash.
This vulnerability was found in the XSR-1800 series of routers with firmware version 7.0.0.0. Other device models and firmware versions may also be affected.
Enterasys XSR Security Routers are reported prone to a denial of service vulnerability.
When these devices pass packets with the IP record route option, they will reportedly crash.
This vulnerability was found in the XSR-1800 series of routers with firmware version 7.0.0.0. Other device models and firmware versions may also be affected.
Exploit / POC
Enterasys XSR Security Router Record Route Denial Of Service Vulnerability
No exploit is required; this issue may be exploited using packet-crafting tools such as hping.
No exploit is required; this issue may be exploited using packet-crafting tools such as hping.
Solution / Fix
Enterasys XSR Security Router Record Route Denial Of Service Vulnerability
Solution:
It is reported that fixes to address this issue are expected to be available by 7/13/2004. Customers are advised to contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that fixes to address this issue are expected to be available by 7/13/2004. Customers are advised to contact the vendor for further details.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Enterasys XSR Security Router Record Route Denial Of Service Vulnerability
References:
References:
- Enterasys XSR Product Home Page (Enterasys)
- ETS-i-2004-11036 Record route option can cause a reboot on the XSR platform (Enterasys)
- Enterasys XSR Security Router Record Route Denial Of Service Vulnerability (More ("Frederico Queiroz"
) - Enterasys XSR Security Routers DoS ("Frederico Queiroz"
)