Release date:
Updated on:
Affected Systems:
Cisco 7200
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49049
Vro products of multiple manufacturers have remote security vulnerabilities due to OSPF protocol specification design errors.
Remote attackers need to connect the router to the victim network, and also need the encryption key for LSA traffic. Then, by enticing network users to accept LSA updates at the controlled router, they can create a network router loop, attackers can exploit these vulnerabilities to cause DoS attacks and perform unauthorized operations.
<* Source: Gabi Nakibly
Link: http://www.networkworld.com/news/2011/080411-blackhat-ospf-vulnerability.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.cisco.com/warp/public/707/advisory.html