CVE-2013-0149
published 2013-08-05CVE-2013-0149: The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS…
PriorityP429medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
2.48%
82.7th percentile
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.
Affected
666 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| brocade | vyatta_vrouter_software | <= 6.6 | — |
| checkpoint | gaia_os | — | — |
| checkpoint | gaia_os | — | — |
| checkpoint | ipso_os | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | asa_5500 | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
vendor_cisco5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mwjr-hhj9-gph9: The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packet
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7310 [MEDIUM] GHSA-mwjr-hhj9-gph9: The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packet
The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-r3f3-f3vp-h6w9: The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate Link State ID values in Link S
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7314 [MEDIUM] GHSA-r3f3-f3vp-h6w9: The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate Link State ID values in Link S
The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-7qx7-x5h7-hv59: The OSPF implementation on the Brocade Vyatta vRouter with software before 6
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7307 [MEDIUM] GHSA-7qx7-x5h7-hv59: The OSPF implementation on the Brocade Vyatta vRouter with software before 6
The OSPF implementation on the Brocade Vyatta vRouter with software before 6.6R1 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-qfjv-vc8r-v59q: The OSPF implementation in IBM i 6
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-5385 [MEDIUM] CWE-20 GHSA-qfjv-vc8r-v59q: The OSPF implementation in IBM i 6
The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-hjvh-w7fp-3j53: The OSPF implementation in Check Point Gaia OS R75
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7311 [MEDIUM] GHSA-hjvh-w7fp-3j53: The OSPF implementation in Check Point Gaia OS R75
The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-4j55-mgmq-6r7m: The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-4806 [MEDIUM] GHSA-4j55-mgmq-6r7m: The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C
The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-6p9f-747c-m7w6: The OSPF implementation in Juniper Junos through 13
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7313 [MEDIUM] GHSA-6p9f-747c-m7w6: The OSPF implementation in Juniper Junos through 13
The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-jj32-rpxp-wv7w: The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA)
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7309 [MEDIUM] GHSA-jj32-rpxp-wv7w: The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA)
The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-7xj8-hhvj-gvwf: The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7308 [MEDIUM] GHSA-7xj8-hhvj-gvwf: The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2
The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2.20.B017 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-639x-j77p-9962: The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packe
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7306 [MEDIUM] CWE-20 GHSA-639x-j77p-9962: The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packe
The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-cr2r-7r8w-gxj8: The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisem
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2013-7312 [MEDIUM] GHSA-cr2r-7r8w-gxj8: The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisem
The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
GHSA
GHSA-p37g-cwqg-c54c: The OSPF implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-05
CVE-2013-0149 [MEDIUM] GHSA-p37g-cwqg-c54c: The OSPF implementation in Cisco IOS 12
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.
Juniper
CVE-2013-7313: The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID
vendor_juniper·2014-01-23·CVSS 5.4
CVE-2013-7313 [MEDIUM] CVE-2013-7313: The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID
CVE-2013-7313: The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
Cisco
OSPF LSA Manipulation Vulnerability in Multiple Cisco Products
vendor_cisco·2013-08-01·CVSS 5.8
CVE-2013-0149 [MEDIUM] CWE-20 OSPF LSA Manipulation Vulnerability in Multiple Cisco Products
OSPF LSA Manipulation Vulnerability in Multiple Cisco Products
Multiple Cisco products are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an unauthenticated attacker to take full control of the OSPF Autonomous System (AS) domain routing table, blackhole traffic, and intercept traffic.
The attacker could trigger this vulnerability by injecting crafted OSPF packets. Successful exploitation could cause flushing of the routing table on a targeted router, as well as propagation of the crafted OSPF LSA type 1 update throughout the OSPF AS domain.
To exploit this vulnerability, an attacker must accurately determine certain parameters within the LSA database on the target router.
Red Hat
(ospfd): Possibility to use invalid / duplicate LSA information (VU#229804)
vendor_redhat·2013-08-01·CVSS 5.8
CVE-2013-0149 [MEDIUM] (ospfd): Possibility to use invalid / duplicate LSA information (VU#229804)
(ospfd): Possibility to use invalid / duplicate LSA information (VU#229804)
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.
Statement: Not vulnerable. This issue did not affect the versions of quagga as shipped with Red Hat Enterprise Linux 5 and 6, since the OSPF protocol implementation in Quagga performs L
Cisco
OSPF LSA Manipulation Vulnerability in Multiple Cisco Products
vendor_cisco
CVE-2013-0149 OSPF LSA Manipulation Vulnerability in Multiple Cisco Products
CVE-2013-0149: OSPF LSA Manipulation Vulnerability in Multiple Cisco Products
Multiple Cisco products are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an unauthenticated attacker to take full control of the OSPF Autonomous System (AS) domain routing table, blackhole traffic, and intercept traffic. The attacker could trigger this vulnerability by injecting crafted OSPF packets. Successful exploitation could cause flushing of the routing table on a targeted router, as well as propagation of the crafted OSPF LSA type 1 update throughout the OSPF AS domain. To exploit this vulnerability, an attacker must accurately determine certain parameters within the LSA database on the tar
No detection rules found.
No public exploits indexed.
Trendmicro
Do Online Mainframes Compomise Business Processes?
blogs_trendmicro·2017-07-13
Do Online Mainframes Compomise Business Processes?
# Do Online Mainframes Compomise Business Processes?
Exposing a mainframe online, even unintentionally, can be detrimental to the security not only of the company’s crown jewels, but also their customers. This is what we found using data from Shodan, a search engine for internet-connected devices.
By: Roel Reyes, Philippe Lin, David Sancho, Morton Swimmer
2017/07/13
Read time: ( words)
Save to Folio
Legacy mainframes are still used by enterprises to handle big data transactions across a range of industries, from financial institutions, telecoms, and internet service providers (ISPs) to airlines and government agencies.
Why are they still in use? As the saying goes: “if it ain’t broke, don’t fix it”. But what if they’re not necessarily “broken”—but unsecure? Exposing a mainframe onlin
Bugzilla
CVE-2013-0149 quagga (ospfd): Possibility to use invalid / duplicate LSA information (VU#229804)
bugzilla·2013-08-02·CVSS 5.8
CVE-2013-0149 [MEDIUM] CVE-2013-0149 quagga (ospfd): Possibility to use invalid / duplicate LSA information (VU#229804)
CVE-2013-0149 quagga (ospfd): Possibility to use invalid / duplicate LSA information (VU#229804)
A security flaw was found in the way how certain Open Shortest Path First (OSPF) protocol implementations used to perform Link State Advertisement (LSA) identifiers lookup in the LSA database during the routing table calculation phase (certain implementations searched for LSA id using only Link State ID). On certain implementations a remote attacker could use this flaw to subvert the routing table of the victim router by sending false link state advertisements on behalf of other routers (resulting into situation where the victim router would drop the entire table [denial of service] or re-route the network traffic).
References:
[1] http://www.kb.cert.org/vuls/id/229804
[2] https://bugzilla.no
Bugzilla
CVE-2013-0630 flash-plugin: buffer overflow flaw that can lead to arbitrary code execution (APSB13-01)
bugzilla·2013-01-08·CVSS 10.0
CVE-2013-0630 [CRITICAL] CVE-2013-0630 flash-plugin: buffer overflow flaw that can lead to arbitrary code execution (APSB13-01)
CVE-2013-0630 flash-plugin: buffer overflow flaw that can lead to arbitrary code execution (APSB13-01)
Adobe security bulletin APSB13-01 describes a security flaw that could cause Adobe Flash Player to crash and potentially allow an attacker to take control of the affected system:
These updates resolve a buffer overflow vulnerability that could lead to code execution (CVE-2013-0630).
External References:
http://www.adobe.com/support/security/bulletins/apsb13-01.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2013:0149 https://rhn.redhat.com/errata/RHSA-2013-0149.html
arXiv
Formal Black-Box Analysis of Routing Protocol Implementations
arxiv_fulltext·2017-09-23
Formal Black-Box Analysis of Routing Protocol Implementations
Formal Black-Box Analysis of Routing Protocol Implementations
Adi Sosnovich Orna Grumberg
Computer Science Department
Technion -- Israel Institute of Technology
Gabi Nakibly
Rafael -- Advanced Defense Systems Ltd.
empty
## Abstract
The Internet infrastructure relies entirely on open standards for its routing protocols. However, the overwhelming majority of routers on the Internet are proprietary and closed-source. Hence, there is no straightforward way to analyze them. Specifically, one cannot easily and systematically identify deviations of a router's routing functionality from the routing protocol's standard. Such deviations (either deliberate or inadvertent) are particularly important to identify since they present non-standard functionalities which have not been openly and rigo
2013-08-05
Published