PT-2013-1007 · Cisco+2 · Cisco Nx-Os+10

Gabi Nakibly

·

Publicado

2013-05-08

·

Atualizado

2014-07-08

·

CVE-2013-0149

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.0 through 12.4 Cisco IOS versions 15.0 through 15.3 Cisco IOS-XE versions 2.x through 3.9.xS Cisco ASA and PIX versions 7.x through 9.1 Cisco FWSM Cisco NX-OS Cisco StarOS versions prior to 14.0.50488
Description The OSPF implementation in Cisco products does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database. This allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a unicast or multicast packet. An attacker could trigger this vulnerability by injecting crafted OSPF packets, potentially causing flushing of the routing table on a targeted router and propagation of the crafted OSPF LSA type 1 update throughout the OSPF AS domain.
Recommendations For Cisco IOS versions 12.0 through 12.4, update to a fixed version. For Cisco IOS versions 15.0 through 15.3, update to a fixed version. For Cisco IOS-XE versions 2.x through 3.9.xS, update to a fixed version. For Cisco ASA and PIX versions 7.x through 9.1, update to a fixed version. For Cisco FWSM, update to a fixed version. For Cisco NX-OS, update to a fixed version. For Cisco StarOS versions prior to 14.0.50488, update to version 14.0.50488 or later. As a temporary workaround, consider restricting access to the OSPF protocol to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00041
CVE-2013-0149
SUSE-SU-2013_1470-1
SUSE-SU-2014_0879-1

Produtos afetados

Check Point Gaia
Cisco Asa
Cisco Fwsm
Cisco Ios
Cisco Ios-Xe
Cisco Ios Xe
Cisco Nx-Os
Cisco Nexus
Cisco Pix
Cisco Staros
Suse