Multiple Juniper Products Remote Security Bypass Vulnerability
BID:65169
Info
Multiple Juniper Products Remote Security Bypass Vulnerability
| Bugtraq ID: | 65169 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-7313 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2014 12:00AM |
| Updated: | Jan 23 2014 12:00AM |
| Credit: | Dr. Gabi Nakibly from Rafael Advanced Defense Systems as joint work he conducted with Eitan Menahem, Yuval Elovici and Ariel Waizel of Telekom Innovation Laboratories at Ben Gurion University |
| Vulnerable: |
Juniper screenos 6.3 Juniper screenos 6.2 Juniper screenos 6.1 Juniper screenos 6.0 Juniper screenos 5.4 Juniper Junos 9.6 Juniper Junos 9.5 Juniper Junos 9.4 Juniper Junos 9.2 Juniper Junos 9.1 Juniper Junos 9.0 Juniper Junos 8.4 Juniper Junos 8.3 Juniper Junos 8.2 Juniper Junos 8.1 Juniper Junos 8.0 Juniper Junos 7.6 Juniper Junos 7.5 Juniper Junos 7.4 Juniper Junos 7.3 Juniper Junos 7.2 Juniper Junos 7.1 Juniper Junos 7.0 Juniper Junos 6.4 Juniper Junos 6.3 Juniper Junos 6.2 Juniper Junos 6.1 Juniper Junos 6.0 Juniper Junos 5.7 Juniper Junos 5.6 Juniper Junos 5.5 Juniper Junos 5.4 Juniper Junos 5.3 Juniper Junos 5.2 Juniper Junos 5.1 Juniper Junos 5.0R4 Juniper Junos 5.0R3 Juniper Junos 5.0 Juniper Junos 4.4 Juniper Junos 4.3 Juniper Junos 4.2 Juniper Junos 4.1 Juniper Junos 4.0 Juniper Junos 13.3 Juniper Junos 13.2 Juniper Junos 13.1 Juniper Junos 12.1X46 Juniper Junos 12.1X45 Juniper Junos 12.1X44 Juniper Junos 12.1R Juniper Junos 12.1 Juniper Junos 11.4X27 Juniper Junos 11.4R9 Juniper Junos 11.4R8 Juniper Junos 11.4R10 Juniper Junos 11.4 Juniper Junos 11.3 Juniper Junos 11.2 Juniper Junos 11.1 Juniper Junos 11.0 |
| Not Vulnerable: | |
Discussion
Multiple Juniper Products Remote Security Bypass Vulnerability
Multiple Juniper Products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Multiple Juniper Products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Exploit / POC
Multiple Juniper Products Remote Security Bypass Vulnerability
An attacker can exploit this issue using readily available network tools.
An attacker can exploit this issue using readily available network tools.
Solution / Fix
Multiple Juniper Products Remote Security Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple Juniper Products Remote Security Bypass Vulnerability
References:
References:
- Juniper HomePage (Juniper)
- Juniper Networks, Inc. Information for VU#229804 (Carnegie Mellon University)
- Open Shortest Path First (OSPF) Protocol does not specify unique LSA lookup iden (Carnegie Mellon University)