Cisco Catalyst Unicast Traffic Broadcast Vulnerability
BID:4790
Info
Cisco Catalyst Unicast Traffic Broadcast Vulnerability
| Bugtraq ID: | 4790 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2002 12:00AM |
| Updated: | May 21 2002 12:00AM |
| Credit: | Vulnerability discovery credited to TROY COULOMBE <[email protected]>. |
| Vulnerable: |
Cisco Catalyst 4000 7.1.2 Cisco Catalyst 4000 6.3.5 Cisco Catalyst 4000 5.5.5 |
| Not Vulnerable: | |
Discussion
Cisco Catalyst Unicast Traffic Broadcast Vulnerability
Catalyst is a commercial-grade switch distributed by Cisco.
Under normal circumstances, a switch will learn the MAC address of a system connected to a port after one packet. It has been reported that the switch may not learn the MAC of a connected system until several more packets have been sent to the unknown host. By doing so, unicast traffic between two systems across the switch may be broadcast to all systems connected to the switch.
Catalyst is a commercial-grade switch distributed by Cisco.
Under normal circumstances, a switch will learn the MAC address of a system connected to a port after one packet. It has been reported that the switch may not learn the MAC of a connected system until several more packets have been sent to the unknown host. By doing so, unicast traffic between two systems across the switch may be broadcast to all systems connected to the switch.
Solution / Fix
Cisco Catalyst Unicast Traffic Broadcast Vulnerability
References
Cisco Catalyst Unicast Traffic Broadcast Vulnerability
References:
References: