Westell Versalink 327W LanD Packet Denial Of Service Vulnerability
BID:15869
Info
Westell Versalink 327W LanD Packet Denial Of Service Vulnerability
| Bugtraq ID: | 15869 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2005 12:00AM |
| Updated: | Dec 14 2005 12:00AM |
| Credit: | Justin M. Wray <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Westell Versalink 327W |
| Not Vulnerable: | |
Discussion
Westell Versalink 327W LanD Packet Denial Of Service Vulnerability
Westell Versalink 327W is prone to a denial of service vulnerability.
These devices are susceptible to a remote denial of service vulnerability when handling TCP 'LanD' packets.
This issue allows remote attackers to crash affected devices, or to temporarily block further network routing functionality. This will deny further network services to legitimate users.
Westell Versalink 327W is reportedly affected by this issue. Due to code reuse among devices, other devices may also be affected.
Westell Versalink 327W is prone to a denial of service vulnerability.
These devices are susceptible to a remote denial of service vulnerability when handling TCP 'LanD' packets.
This issue allows remote attackers to crash affected devices, or to temporarily block further network routing functionality. This will deny further network services to legitimate users.
Westell Versalink 327W is reportedly affected by this issue. Due to code reuse among devices, other devices may also be affected.
Exploit / POC
Westell Versalink 327W LanD Packet Denial Of Service Vulnerability
No exploit is required.
The following Hping2 command is sufficient to crash affected devices. The IP addresses must both be configured on the targeted device:
hping2 -A -S -P -U 1.2.3.4 -s 80 -p 80 -a 192.168.1.1
No exploit is required.
The following Hping2 command is sufficient to crash affected devices. The IP addresses must both be configured on the targeted device:
hping2 -A -S -P -U 1.2.3.4 -s 80 -p 80 -a 192.168.1.1
Solution / Fix
Westell Versalink 327W LanD Packet Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Westell Versalink 327W LanD Packet Denial Of Service Vulnerability
References:
References:
- Westell Products Page (Westell)
- RLA ("Remote LanD Attack") (Synister Syntax
)