exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

cabletron.ssr.dos.txt

cabletron.ssr.dos.txt
Posted Nov 25, 1999
Site bindview.com

Bindview Security Advisory: Denial of Service Vulnerability in Cabletron's SmartSwitch Router (SSR). Remote users can flood the ARP table and stop the processing of packets.

tags | exploit, remote, denial of service
SHA-256 | 85b52a0144618cc558cd1f34d6755e7f885a84a66d835af7ef076846c52575a7

cabletron.ssr.dos.txt

Change Mirror Download
Bindview Security Advisory
--------

Cabletron SmartSwitch Router 8000 Firmware v2.x
Issue date: November 24, 1999
Contact: Scott Blake <blake@bos.bindview.com>

Topic:
Denial of Service Vulnerability in Cabletron's SmartSwitch Router (SSR)

Overview:
Cabletron's SSR is a Layers 2-4 routing and switching device with one of
the fastest switching architectures in the industry. Attackers can cause
the SSR to stop handling any network traffic.

Affected Systems:
Bindview only confirms the vulnerability in the SSR 8000 running firmware
revision 2.x. Due to the nature of the problem, other equipment may
be vulnerable, including other manufacturers' products.

Impact:
A malicious attacker can cause the SSR to stop functioning for as long
as the attacker can continue feeding packets to the device.

Details:
Cabletron indicates that the bottleneck appears to occur in the ARP handling
mechanism of the SSR. The SSR appears to only be capable of handling ~200
ARP requests per second. Thus, by initiating network traffic to more than
this critical number of IP addresses, an attacker can cause the router to
stop
functioning while the ARP handler is flooded. In extreme cases, with input
rates only available on the local network, it may be possible to corrupt the
SSR's configuration with a sustained flood of new IP addresses.

The danger in this problem arises from the fact that many perimeter defenses
(firewalls) permit ICMP through, which means that remote, anonymous
attackers
may be able to crash the SSR.



Fix Information:

Upgrade your SSR firmware to version 3.x:
http://www.cabletron.com/download/download.cgi?lib=ssr

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close