Lucent Brick Spoofed Address Communication Denial Of Service Vulnerability
BID:5337
Info
Lucent Brick Spoofed Address Communication Denial Of Service Vulnerability
| Bugtraq ID: | 5337 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2002 12:00AM |
| Updated: | Jul 27 2002 12:00AM |
| Credit: | Vulnerability discovery credited to FX <[email protected]> and kim0 <[email protected]>. |
| Vulnerable: |
Lucent VPN Firewall Brick 80 Lucent VPN Firewall Brick 201 Lucent VPN Firewall Brick 20 Lucent VPN Firewall Brick 1000 |
| Not Vulnerable: | |
Discussion
Lucent Brick Spoofed Address Communication Denial Of Service Vulnerability
Brick is the firewall and VPN management system distributed by Lucent. It is a hardware/firmware solution.
It has been reported that Brick systems may be forced into terminating communication with specific systems. By binding the IP address of a specific system to a different system and pinging the Brick with the specified IP address, the Brick will update it's ARP cache. Upon updating the cache, the Brick terminates communication with the system legitimately using the IP address.
Brick is the firewall and VPN management system distributed by Lucent. It is a hardware/firmware solution.
It has been reported that Brick systems may be forced into terminating communication with specific systems. By binding the IP address of a specific system to a different system and pinging the Brick with the specified IP address, the Brick will update it's ARP cache. Upon updating the cache, the Brick terminates communication with the system legitimately using the IP address.
Exploit / POC
Lucent Brick Spoofed Address Communication Denial Of Service Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Lucent Brick Spoofed Address Communication Denial Of Service Vulnerability
Solution:
Do not enable the "Floating MAC" option. By default, this option is disabled.
Lucent reports that VPN Firewall 7.0 will provide additional security features which mitigate this issue. Reportedly, VPN Firewall 7.0 is scheduled for release in September 2002.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Do not enable the "Floating MAC" option. By default, this option is disabled.
Lucent reports that VPN Firewall 7.0 will provide additional security features which mitigate this issue. Reportedly, VPN Firewall 7.0 is scheduled for release in September 2002.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Lucent Brick Spoofed Address Communication Denial Of Service Vulnerability
References:
References:
- Phenoelit Advisory
(Phenoelit Group)