Vulnerability Name: | CVE-2005-4437 (CCN-23746) | ||||||||
Assigned: | 2005-12-19 | ||||||||
Published: | 2005-12-19 | ||||||||
Updated: | 2018-10-19 | ||||||||
Summary: | MD5 Neighbor Authentication in Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS 11.3 and later, does not include the Message Authentication Code (MAC) in the checksum, which allows remote attackers to sniff message hashes and (1) replay EIGRP HELLO messages or (2) cause a denial of service by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Dec 19 2005 - 11:17:15 CST Authenticated EIGRP DoS / Information leak Source: CCN Type: Full-Disclosure Mailing List, Mon Dec 19 2005 - 18:39:36 CST RE: Authenticated EIGRP DoS / Information leak Source: MITRE Type: CNA CVE-2005-4437 Source: FULLDISC Type: Vendor Advisory 20051219 Authenticated EIGRP DoS / Information leak Source: FULLDISC Type: UNKNOWN 20051220 RE: Authenticated EIGRP DoS / Information leak Source: SREASON Type: UNKNOWN 274 Source: CCN Type: SECTRACK ID: 1015382 Cisco IOS EIGRP Bugs Let Remote Users Deny Service or Obtain Potentially Sensitive Information Source: SECTRACK Type: UNKNOWN 1015382 Source: CCN Type: Cisco Security Notice: Document ID 68459 Cisco Security Notice: Response to Full-Disclosure - Multiple Vulnerabilities within Cisco EIGRP Source: CCN Type: OSVDB ID: 22109 Multiple Vendor EIGRP HELLO Packet Replay Information Disclosure Source: BUGTRAQ Type: UNKNOWN 20051219 Authenticated EIGRP DoS / Information leak Source: BUGTRAQ Type: UNKNOWN 20051220 Re: Unauthenticated EIGRP DoS Source: CCN Type: BID-14877 Cisco IOS EIGRP Goodbye Message Denial Of Service and Unauthorized Access Vulnerability Source: BID Type: UNKNOWN 15970 Source: CCN Type: BID-15970 Cisco EIGRP Protocol HELLO Packet Replay Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-3008 Source: CCN Type: IBM Internet Security Systems X-Force Database Cisco IOS spoofed EIGRP announcement flood denial of service Source: XF Type: UNKNOWN eigrp-hello-replay-info-leak(23746) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5741 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |