Nortel Networks Multiple Products Remote Denial of Service Vulnerability
BID:13792
Info
Nortel Networks Multiple Products Remote Denial of Service Vulnerability
| Bugtraq ID: | 13792 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-1802 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | NTA Monitor is credited with the discovery of this vulnerability. |
| Vulnerable: |
Nortel Networks VPN Router 600 0 Nortel Networks VPN Router 5000 Nortel Networks VPN Router 2700 Nortel Networks VPN Router 1740 Nortel Networks VPN Router 1700 Nortel Networks VPN Router 1100 Nortel Networks VPN Router 1050 Nortel Networks VPN Router 1010 Nortel Networks Contivity 4600 Secure IP Services Gateway Nortel Networks Contivity 4500 Secure IP Services Gateway Nortel Networks Contivity 4000 VPN Switch Nortel Networks Contivity 2600 Secure IP Services Gateway Nortel Networks Contivity 2500 VPN Switch Nortel Networks Contivity 2000 VPN Switch Nortel Networks Contivity 1600 Secure IP Services Gateway Nortel Networks Contivity 1500 VPN Switch Nortel Networks Contivity 1000 VPN Switch |
| Not Vulnerable: | |
Discussion
Nortel Networks Multiple Products Remote Denial of Service Vulnerability
Multiple Nortel Networks products are prone to a remote denial of service vulnerability.
The issue manifests when the affected appliance processes an IKE main packet (ISAKMP) header of a certain type.
When the packet is processed, the vulnerability is triggered and the device crashes, effectively denying service for legitimate users.
Multiple Nortel Networks products are prone to a remote denial of service vulnerability.
The issue manifests when the affected appliance processes an IKE main packet (ISAKMP) header of a certain type.
When the packet is processed, the vulnerability is triggered and the device crashes, effectively denying service for legitimate users.
Exploit / POC
Nortel Networks Multiple Products Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Nortel Networks Multiple Products Remote Denial of Service Vulnerability
Solution:
It is reported that this issue is addressed by version 05-05.200 of the firmware. This is not confirmed.
Nortel has released an advisory to address this issue. Please see the advisory in Web references for more information.
Solution:
It is reported that this issue is addressed by version 05-05.200 of the firmware. This is not confirmed.
Nortel has released an advisory to address this issue. Please see the advisory in Web references for more information.
References
Nortel Networks Multiple Products Remote Denial of Service Vulnerability
References:
References:
- 328562 - VPN Router DOS Vulnerability (Nortel Networks)
- Nortel VPN Router DOS (NTA Monitor)
- Nortel VPN Router Malformed Packet DoS Vulnerability (Roy Hills
)