Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
BID:16479
Info
Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
| Bugtraq ID: | 16479 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 02 2006 12:00AM |
| Updated: | Feb 13 2006 04:33PM |
| Credit: | "Hatch, Stephen A" <[email protected]> reported this issue to the vendor. |
| Vulnerable: |
Nortel Networks VPN Router 600 0 Nortel Networks VPN Router 5000 Nortel Networks VPN Router 2700 Nortel Networks VPN Router 1740 Nortel Networks VPN Router 1700 Nortel Networks VPN Router 1100 Nortel Networks VPN Router 1050 Nortel Networks VPN Router 1010 Nortel Networks VPN Router Nortel Networks Contivity VPN Client 5.0 1_100 Nortel Networks Contivity VPN Client 5.0 1_030 Nortel Networks Contivity VPN Client 4.91 Nortel Networks Contivity VPN Client 4.86 Nortel Networks Contivity VPN Client 4.60.51 Nortel Networks Contivity 4600 Secure IP Services Gateway Nortel Networks Contivity 4500 Secure IP Services Gateway Nortel Networks Contivity 4000 VPN Switch Nortel Networks Contivity 2600 Secure IP Services Gateway Nortel Networks Contivity 2500 VPN Switch Nortel Networks Contivity 2000 VPN Switch Nortel Networks Contivity 1600 Secure IP Services Gateway Nortel Networks Contivity 1500 VPN Switch Nortel Networks Contivity 1000 VPN Switch |
| Not Vulnerable: | |
Discussion
Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
Multiple Nortel Networks products are reportedly prone to a remote denial-of-service vulnerability. The specific content and type of network traffic sufficient to trigger this issue are currently unknown.
This issue is reportedly being tracked by Nortel as support case 060110-04843.
When the network traffic is processed, the vulnerability is triggered, and the IPSec software fails to process further ESP traffic, effectively denying service for legitimate users.
Nortel IPSec client software version v04_60.51 and newer is reportedly susceptible to this issue.
Further reports indicate this issue is exploitable only through an existing IPSec tunnel and only via a valid remote access account.
NOTE: Further analysis and reports have indicated that this issue is limited to the VPN Client. Therefore, we have determined that this does not present a security threat. This BID is being retired.
Multiple Nortel Networks products are reportedly prone to a remote denial-of-service vulnerability. The specific content and type of network traffic sufficient to trigger this issue are currently unknown.
This issue is reportedly being tracked by Nortel as support case 060110-04843.
When the network traffic is processed, the vulnerability is triggered, and the IPSec software fails to process further ESP traffic, effectively denying service for legitimate users.
Nortel IPSec client software version v04_60.51 and newer is reportedly susceptible to this issue.
Further reports indicate this issue is exploitable only through an existing IPSec tunnel and only via a valid remote access account.
NOTE: Further analysis and reports have indicated that this issue is limited to the VPN Client. Therefore, we have determined that this does not present a security threat. This BID is being retired.
Exploit / POC
Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
An exploit is not likely required.
An exploit is not likely required.
Solution / Fix
Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nortel Networks Multiple IPSec Products Remote Denial of Service Vulnerability
References:
References:
- Nortel Networks Homepage (Nortel Networks)
- Security Advisory Bulletins (Nortel Networks)