Cisco EIGRP Protocol HELLO Packet Replay Vulnerability
BID:15970
Info
Cisco EIGRP Protocol HELLO Packet Replay Vulnerability
| Bugtraq ID: | 15970 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 19 2005 12:00AM |
| Credit: | "Andrew A. Vladimirov" <[email protected]>, Arhont Ltd disclosed this weakness. |
| Vulnerable: |
Cisco EIGRP 1.2 |
| Not Vulnerable: | |
Discussion
Cisco EIGRP Protocol HELLO Packet Replay Vulnerability
The Cisco EIGRP protocol is susceptible to a vulnerability that allows HELLO packet replay attacks.
This issue allows attackers to gain access to potentially sensitive network information in EIGRP UPDATE reply packets, or to cause a denial of service condition by flooding routers with HELLO packets.
The denial of service issue is described in BID 6443 (Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability). By utilizing replayed HELLO packets with MD5 enabled, attackers may cause a more severe denial of service condition.
This issue is being tracked by Cisco Bug ID CSCsc13724.
The Cisco EIGRP protocol is susceptible to a vulnerability that allows HELLO packet replay attacks.
This issue allows attackers to gain access to potentially sensitive network information in EIGRP UPDATE reply packets, or to cause a denial of service condition by flooding routers with HELLO packets.
The denial of service issue is described in BID 6443 (Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability). By utilizing replayed HELLO packets with MD5 enabled, attackers may cause a more severe denial of service condition.
This issue is being tracked by Cisco Bug ID CSCsc13724.
Exploit / POC
Cisco EIGRP Protocol HELLO Packet Replay Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Cisco EIGRP Protocol HELLO Packet Replay Vulnerability
Solution:
Cisco has replied to the original email message, and has confirmed this issue. Please see the referenced message for further information on mitigating this issue.
Solution:
Cisco has replied to the original email message, and has confirmed this issue. Please see the referenced message for further information on mitigating this issue.
References
Cisco EIGRP Protocol HELLO Packet Replay Vulnerability
References:
References:
- Cisco Call Manager Express (Cisco Systems)
- Cisco IOS Software (Cisco Systems)
- Authenticated EIGRP DoS / Information leak ("Andrew A. Vladimirov"
) - Re: Unauthenticated EIGRP DoS ("Paul Oxman \(poxman\)"
)