CVE-2005-4437

MD5 Neighbor Authentication in Extended Interior Gateway Routing Protocol (EIGRP) 1.2, as implemented in Cisco IOS 11.3 and later, does not include the Message Authentication Code (MAC) in the checksum, which allows remote attackers to sniff message hashes and (1) replay EIGRP HELLO messages or (2) cause a denial of service by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:extended_interior_gateway_routing_protocol:extended_interior_gateway_routing_protocol:1.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:04

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040332.html - Vendor Advisory () http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/040332.html - Vendor Advisory
References () http://marc.info/?l=full-disclosure&m=113504451523186&w=2 - () http://marc.info/?l=full-disclosure&m=113504451523186&w=2 -
References () http://securityreason.com/securityalert/274 - () http://securityreason.com/securityalert/274 -
References () http://securitytracker.com/id?1015382 - () http://securitytracker.com/id?1015382 -
References () http://www.securityfocus.com/archive/1/419830/100/0/threaded - () http://www.securityfocus.com/archive/1/419830/100/0/threaded -
References () http://www.securityfocus.com/archive/1/419898/100/0/threaded - () http://www.securityfocus.com/archive/1/419898/100/0/threaded -
References () http://www.securityfocus.com/bid/15970 - () http://www.securityfocus.com/bid/15970 -
References () http://www.vupen.com/english/advisories/2005/3008 - () http://www.vupen.com/english/advisories/2005/3008 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5741 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5741 -

Information

Published : 2005-12-21 01:03

Updated : 2024-11-21 00:04


NVD link : CVE-2005-4437

Mitre link : CVE-2005-4437

CVE.ORG link : CVE-2005-4437


JSON object : View

Products Affected

extended_interior_gateway_routing_protocol

  • extended_interior_gateway_routing_protocol