First published: Mon Aug 12 2013(Updated: )
The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP 3Com Router | =3012 | |
HP 3Com Router | =3018 | |
HP 3Com Router | =5012 | |
HP 3Com Router | =5232 | |
HP 3Com Router | =5642 | |
HP 3Com Router | =5642_taa | |
HP 3Com Router | =5682 | |
HP 5500-24G-4SFP Hi Switch | =jg311a | |
HP 5500-24G-PoE EI Switch | =jd378a | |
HP 5500-24G-PoE Si Switch | =jd371a | |
HP 5500-24G-SFP DC EI Switch | =jd379a | |
HP 5500-24G-SFP EI Switch | =jd374a | |
HP 5500-24G-SFP DC EI Switch | =jd373a | |
HP 5500-24G DC EI Switch | =jd377a | |
HP 5500-24G SI Switch | =jd369a | |
HP 5500-48G-PoE EI Switch | =jd376a | |
HP 5500-48G-PoE SI Switch | =jd372a | |
HP 5500-48G EI Switch | =jd375a | |
HP 5500-48G-PoE SI Switch | =jd370a | |
HP 5500G-24 EI Switch | =jf551a | |
HP 5500G-24 EI SFP Switch | =jf553a | |
HP 5500G-48 EI Switch | =jf552a | |
H3C Routing Switch | =s5600-26c | |
H3C Routing Switch | =s5600-26c-pwr | |
H3C Routing Switch | =s5600-26f | |
H3C Routing Switch | =s5600-50c | |
H3C Routing Switch | =s5600-50c-pwr |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4806 is classified as a high-severity vulnerability affecting multiple HP routers and switches.
To fix CVE-2013-4806, ensure that you apply the latest firmware updates released by HP for the affected devices.
CVE-2013-4806 affects HP JD9##A routers, HP J4###A, J484#B, J8###A switches, along with various HP 3COM and H3C devices.
CVE-2013-4806 is a vulnerability in the OSPF implementation that allows for duplicate Link State IDs, potentially leading to routing issues.
CVE-2013-4806 was reported in 2013 and remains relevant for the affected HP networking devices.