Cisco EIGRP Protocol Unauthenticated Goodbye Packet Remote Denial Of Service Vulnerability
BID:15978
Info
Cisco EIGRP Protocol Unauthenticated Goodbye Packet Remote Denial Of Service Vulnerability
| Bugtraq ID: | 15978 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Dec 19 2005 12:00AM |
| Credit: | "Andrew A. Vladimirov" <[email protected]>, Arhont Ltd disclosed this issue. |
| Vulnerable: |
Cisco EIGRP 1.2 |
| Not Vulnerable: | |
Discussion
Cisco EIGRP Protocol Unauthenticated Goodbye Packet Remote Denial Of Service Vulnerability
The Cisco EIGRP protocol is susceptible to a remote denial of service vulnerability. This issue is possible when MD5 neighbor authentication is not in use.
This issue allows attackers to cause routing relationships to be torn down, forcing them to be reestablished. The routing link will be unavailable during the time that the link is torn down, until it is reestablished. By repeating the attack, a sustained denial of network service is possible.
This issue is being tracked by Cisco Bug ID CSCsc13698.
The Cisco EIGRP protocol is susceptible to a remote denial of service vulnerability. This issue is possible when MD5 neighbor authentication is not in use.
This issue allows attackers to cause routing relationships to be torn down, forcing them to be reestablished. The routing link will be unavailable during the time that the link is torn down, until it is reestablished. By repeating the attack, a sustained denial of network service is possible.
This issue is being tracked by Cisco Bug ID CSCsc13698.
Exploit / POC
Cisco EIGRP Protocol Unauthenticated Goodbye Packet Remote Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Cisco EIGRP Protocol Unauthenticated Goodbye Packet Remote Denial Of Service Vulnerability
Solution:
Cisco has replied to the original email message and has confirmed this issue. Please see the referenced message for further information on mitigating this issue.
Solution:
Cisco has replied to the original email message and has confirmed this issue. Please see the referenced message for further information on mitigating this issue.
References
Cisco EIGRP Protocol Unauthenticated Goodbye Packet Remote Denial Of Service Vulnerability
References:
References:
- Cisco Call Manager Express (Cisco Systems)
- Cisco IOS Software (Cisco Systems)
- Re: Unauthenticated EIGRP DoS ("Paul Oxman \(poxman\)"
)