Multiple NEC Products Remote Security Bypass Vulnerability
BID:65170
Info
Multiple NEC Products Remote Security Bypass Vulnerability
| Bugtraq ID: | 65170 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-7314 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2014 12:00AM |
| Updated: | Jan 27 2014 12:00AM |
| Credit: | Dr. Gabi Nakibly from Rafael Advanced Defense Systems as joint work he conducted with Eitan Menahem, Yuval Elovici and Ariel Waizel of Telekom Innovation Laboratories at Ben Gurion University |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple NEC Products Remote Security Bypass Vulnerability
Multiple NEC Products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Multiple NEC Products are prone to a remote security-bypass vulnerability due to an error in the OSPF protocol specification.
Exploiting this issue could allow an attacker to bypass certain security restrictions and take full control of the OSPF AS domain routing table, blackholed traffic, and intercepted traffic. This may aid in further attacks.
Exploit / POC
Multiple NEC Products Remote Security Bypass Vulnerability
An attacker can exploit this issue using readily available network tools.
An attacker can exploit this issue using readily available network tools.
Solution / Fix
Multiple NEC Products Remote Security Bypass Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Multiple NEC Products Remote Security Bypass Vulnerability
References:
References: