CVE-2000-0221: Medium severity Nortel Nautica Marlin vulnerability
The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If SNMP is not required, disable the SNMP service on the Nautica Marlin device to eliminate the vulnerable SNMP listener.
Nortel Nautica Marlin SNMP = disabled - Compensating control
If SNMP cannot be disabled, block or filter UDP traffic to the SNMP port (UDP/161) from untrusted networks and restrict SNMP management access to a small set of trusted IPs via firewall rules or ACLs. Consider placing the device on a management-only VLAN/segment.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0221?
CVE-2000-0221 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2000-0221?
To mitigate CVE-2000-0221, configure the Nautica Marlin bridge to filter or block zero length UDP packets at the SNMP port.
What are the potential impacts of CVE-2000-0221?
CVE-2000-0221 can disrupt network services by causing a denial of service, impacting availability.
Which devices are affected by CVE-2000-0221?
CVE-2000-0221 affects devices running the Nortel Nautica Marlin software.
Can CVE-2000-0221 be exploited remotely?
Yes, CVE-2000-0221 can be exploited remotely by sending a zero length UDP packet to the SNMP port.