Multiple Enterasys Products Remote Security Bypass Vulnerability
BID:65167
Info
Multiple Enterasys Products Remote Security Bypass Vulnerability
| Bugtraq ID: | 65167 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-7312 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2014 12:00AM |
| Updated: | Jan 23 2014 12:00AM |
| Credit: | Dr. Gabi Nakibly from Rafael Advanced Defense Systems as joint work he conducted with Eitan Menahem, Yuval Elovici and Ariel Waizel of Telekom Innovation Laboratories at Ben Gurion University |
| Vulnerable: |
Enterasys s180 0 Enterasys s155 0 Enterasys s150 0 Enterasys s140 0 Enterasys s130 0 Enterasys k6 0 Enterasys k10 0 Enterasys g3 0 Enterasys c5 0 |
| Not Vulnerable: | |
Discussion
Multiple Enterasys Products Remote Security Bypass Vulnerability
Multiple Enterasys Products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Multiple Enterasys Products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Exploit / POC
Multiple Enterasys Products Remote Security Bypass Vulnerability
An attacker can exploit this issue using readily available network tools.
An attacker can exploit this issue using readily available network tools.
Solution / Fix
Multiple Enterasys Products Remote Security Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple Enterasys Products Remote Security Bypass Vulnerability
References:
References:
- Enterasys Networks Homepage (Enterasys Networks)
- Enterasys Networks Information for VU#229804 (Carnegie Mellon University)
- Open Shortest Path First (OSPF) Protocol does not specify unique LSA lookup iden (Carnegie Mellon University)