Multiple Yamaha Products Remote Security Bypass Vulnerability
BID:65163
Info
Multiple Yamaha Products Remote Security Bypass Vulnerability
| Bugtraq ID: | 65163 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-7310 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2014 12:00AM |
| Updated: | Jan 23 2014 12:00AM |
| Credit: | Dr. Gabi Nakibly from Rafael Advanced Defense Systems as joint work he conducted with Eitan Menahem, Yuval Elovici and Ariel Waizel of Telekom Innovation Laboratories at Ben Gurion University |
| Vulnerable: |
Brocade Vyatta Vrouter Software 6.6 Brocade Vyatta Vrouter 0 |
| Not Vulnerable: | |
Discussion
Multiple Yamaha Products Remote Security Bypass Vulnerability
Multiple Yamaha products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Multiple Yamaha products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Exploit / POC
Multiple Yamaha Products Remote Security Bypass Vulnerability
An attacker can exploit this issue using readily available network tools.
An attacker can exploit this issue using readily available network tools.
Solution / Fix
Multiple Yamaha Products Remote Security Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple Yamaha Products Remote Security Bypass Vulnerability
References:
References:
- Yamaha Homepage (Yamaha Corporation)
- Open Shortest Path First (OSPF) Protocol does not specify unique LSA lookup iden (Carnegie Mellon University)
- Yamaha Corporation Information for VU#229804 (Carnegie Mellon University)