PT-2013-1318 · Check Point · Check Point Gaia+1
Published
2013-02-21
·
Updated
2014-01-23
·
CVE-2013-7311
CVSS v2.0
5.4
Medium
| Vector | AV:A/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Check Point Gaia versions R75.X through R76
Check Point IPSO OS versions 6.2 R75.X through R76
Description
The issue is related to the implementation of the OSPF protocol in the Check Point Gaia operating system, which does not account for duplicate Link State ID values in LSA packets. This can be exploited by sending specially crafted LSA packets, potentially allowing an attacker to cause a denial of service or obtain sensitive information.
Recommendations
For Check Point Gaia versions R75.X through R76, consider disabling the OSPF protocol until a patch is available.
For Check Point IPSO OS versions 6.2 R75.X through R76, restrict access to the LSA database to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Check Point Gaia
Check Point Ipso Os