Multiple Brocade Routers Remote Security Bypass Vulnerability
BID:65157
Info
Multiple Brocade Routers Remote Security Bypass Vulnerability
| Bugtraq ID: | 65157 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-7307 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2014 12:00AM |
| Updated: | Jan 23 2014 12:00AM |
| Credit: | Dr. Gabi Nakibly from Rafael Advanced Defense Systems as joint work he conducted with Eitan Menahem, Yuval Elovici and Ariel Waizel of Telekom Innovation Laboratories at Ben Gurion University |
| Vulnerable: |
Brocade Vyatta Vrouter Software 6.6 Brocade Vyatta Vrouter 0 |
| Not Vulnerable: | |
Discussion
Multiple Brocade Routers Remote Security Bypass Vulnerability
Multiple Brocade routers are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Multiple Brocade routers are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Exploit / POC
Multiple Brocade Routers Remote Security Bypass Vulnerability
An attacker can exploit this issue using readily available network tools.
An attacker can exploit this issue using readily available network tools.
Solution / Fix
Multiple Brocade Routers Remote Security Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple Brocade Routers Remote Security Bypass Vulnerability
References:
References:
- Brocade Homepage (Brocade)
- Open Shortest Path First (OSPF) Protocol does not specify unique LSA lookup iden (Carnegie Mellon University)