HIGH · 7.0

CVE-2013-4806

The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possib...

Vulnerability Description

The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

CVSS Score

7.0

HIGH

AV:N/AC:M/Au:S/C:P/I:N/A:C
Confidentiality
PARTIAL
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
Hp3Com Router3012
Hp5500-24G-4Sfp Hi Switch With 2 Interface Slotsjg311a
Hp5500-24G-Poe Ei Switchjd378a
Hp5500-24G-Poe Si Switchjd371a
Hp5500-24G-Sfp Dc Ei Switchjd379a
Hp5500-24G-Sfp Ei Switchjd374a
Hp5500-24G Dc Ei Switchjd373a
Hp5500-24G Ei Switchjd377a
Hp5500-24G Si Switchjd369a
Hp5500-48G-Poe Ei Switchjd376a
Hp5500-48G-Poe Si Switchjd372a
Hp5500-48G Ei Switchjd375a
Hp5500-48G Si Switchjd370a
Hp5500G-24 Ei 10\/100\/1000 No Power Supply Unit Switchjf551a
Hp5500G-24 Ei Sfp No Power Supply Unit Switchjf553a
Hp5500G-48 Ei 10\/100\/1000 No Power Supply Unit Switchjf552a
HpH3C Ethernet Switchs5600-26c

References

FAQ

What is CVE-2013-4806?

CVE-2013-4806 is a vulnerability with a CVSS score of 7.0 (HIGH). The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possib...

How severe is CVE-2013-4806?

CVE-2013-4806 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4806?

Check the references section above for vendor advisories and patch information. Affected products include: Hp 3Com Router, Hp 5500-24G-4Sfp Hi Switch With 2 Interface Slots, Hp 5500-24G-Poe Ei Switch, Hp 5500-24G-Poe Si Switch, Hp 5500-24G-Sfp Dc Ei Switch.