CVE-2000-0292: Medium severity Adtran MX2800 vulnerability
The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or rate-limit ICMP (ping) traffic to the Adtran MX2800 Ethernet interface at the network edge (firewall, router ACLs or upstream switches) to mitigate ping-flood DoS. Place the device on an isolated/management VLAN and restrict access to trusted IPs only. Implement ICMP flood protection/traffic shaping on upstream devices if available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0292?
CVE-2000-0292 is classified as a denial of service vulnerability that can lead to device crashes.
How do I fix CVE-2000-0292?
To mitigate CVE-2000-0292, ensure that proper network security measures are in place to filter and limit ping requests.
Which devices are affected by CVE-2000-0292?
CVE-2000-0292 specifically affects the Adtran MX2800 M13 Multiplexer.
What type of attack does CVE-2000-0292 involve?
CVE-2000-0292 involves a ping flood attack that can overwhelm the Ethernet interface.
What are the consequences of exploiting CVE-2000-0292?
Exploiting CVE-2000-0292 can cause the affected Adtran MX2800 device to crash, resulting in a denial of service.