Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability
BID:6443
Info
Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability
| Bugtraq ID: | 6443 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2002 12:00AM |
| Updated: | Dec 19 2002 12:00AM |
| Credit: | Vulnerability discovery credited to FX <[email protected]> and the Phenoelit Group. Further research by Arhont Ltd. |
| Vulnerable: |
Cisco IOS 12.2 Cisco IOS 12.1 Cisco IOS 12.0 Cisco IOS 11.3 |
| Not Vulnerable: | |
Discussion
Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability
Internet Operating System (IOS) is the firmware developed and maintained by Cisco for Cisco Routers.
A system sending spoofed EIGRP announcements may cause a denial of service to all routers and systems on a given network segment. Due to improper limits in the attempt to discover routers, a neighbor announcement received by routers on a given network segment will result in an address resolution protocol (ARP) storm, filling network capacity while routers attempt to contact the announcing neighbor. Additionally, resources on the router such as CPU will also become bound while the router attempts to reach the announcing neighbor. It should be noted that it is also possible to exploit this vulnerability on systems that accept EIGRP announcements via unicast.
Internet Operating System (IOS) is the firmware developed and maintained by Cisco for Cisco Routers.
A system sending spoofed EIGRP announcements may cause a denial of service to all routers and systems on a given network segment. Due to improper limits in the attempt to discover routers, a neighbor announcement received by routers on a given network segment will result in an address resolution protocol (ARP) storm, filling network capacity while routers attempt to contact the announcing neighbor. Additionally, resources on the router such as CPU will also become bound while the router attempts to reach the announcing neighbor. It should be noted that it is also possible to exploit this vulnerability on systems that accept EIGRP announcements via unicast.
Exploit / POC
Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cisco IOS EIGRP Announcement ARP Denial Of Service Vulnerability
References:
References:
- Authenticated EIGRP DoS / Information leak ("Andrew A. Vladimirov"
) - Cisco IOS EIGRP Network DoS (FX
) - Re: Cisco IOS EIGRP Network DoS (Damir Rajnovic
)