Secunia Logo  


Secunia PSI WorldMap
 
Nortel Networks Products ICMP Handling Vulnerabilities
Secunia Advisory: SA15761
Release Date: 2005-07-14
Popularity: 8,015 views

Critical:
Less critical
Impact: DoS
Where: From remote
Solution Status: Vendor Workaround

OS:Nortel Access Stack Node (ASN) Router
Nortel Advanced Remote Node (ARN) Router (formerly Passport)
Nortel Application Switches (formerly Alteon)
Nortel Backbone Concentrator Node (BCN) Router
Nortel Backbone Link Node (BLN) Router
Nortel Ethernet Routing Switch 5510 (formerly BayStack)
Nortel Ethernet Routing Switch 5520 (formerly BayStack)
Nortel Ethernet Routing Switch 8600 (formerly Passport)
Nortel Ethernet Switch 420-24T (formerly BayStack)
Nortel Ethernet Switch 425 (formerly BayStack)
Nortel Ethernet Switch 470 (formerly BayStack)
Nortel Multiprotocol Router 2430 (formerly Passport)
Nortel Multiprotocol Router 5430 (formerly Passport)
Nortel Multiservice Access Switch 4400 Series (formerly Passport)
Nortel Multiservice Switch 15000 (formerly Passport)
Nortel Multiservice Switch 20000 (formerly Passport)
Nortel Multiservice Switch 6400 (formerly Passport)
Nortel Multiservice Switch 7400 (formerly Passport)
Nortel Passport 1150 Routing Switch
Nortel Services Edge Router 5500 (formerly Shasta)
Nortel VPN Routers

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Application Switch (Alteon Family):
The vendor recommends using the data port instead of the management port for management traffic or connect the management port to a secured segment of the network.

BayStack family of products:
The vendor has reportedly issued a patch.

VPN Router:
The vendor recommends limiting exposure by disabling the few allowed TCP protocols permitted on the public side if they are not in use (PPTP, HTTPS, SSL, and LDAP).

Ethernet Routing Switch (Passport 8600 Routing Switch):
Update to release 3.5.10.0 or 3.7.7.0.

Multiservice Access Switch 4400 (formerly Passport 4400):
Update to release 4.3.1.7.3.0 , 5.2.0.11.9.0, or 4.0.4.30.8.0.

Ethernet Routing Switch (Passport Family 1100/1150/1200/1250):
A fix is reportedly available.

Services Edge Router (Shasta Family):
The vendor recommends configuring a security IP policy protecting against these types of attacks.

Multiprotocol Router Family:
Patches are available for the 15.6, 15.5, 15.4, and 14.0 release streams.

Original Advisory:
Nortel Networks:
http://www130.nortelnetworks.com/cgi-...1&subtype=&DocumentOID=326515

Other References:
SA14904:
http://secunia.com/advisories/14904/

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

27th Nov, 2009
New advisories: 8
New vulnerabilities: 15
Updated advisories: 11

Moderately // 319 views
Ubuntu update for php5

26th Nov, 2009
New advisories: 15
New vulnerabilities: 37
Updated advisories: 48

Moderately // 477 views
SugarCRM Multiple Vulnerabilities

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 36 views
2. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 33 views
3. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 32 views
4. Oracle Products Multiple Vulnerabilities // 31 views
5. avast! Home/Professional aswRdr.sys Memory Corruption Vulnerability // 28 views
6. Adobe Reader/Acrobat Multiple Vulnerabilities // 28 views
7. Oracle Products Multiple Vulnerabilities // 28 views
8. Adobe Flash Player Multiple Vulnerabilities // 26 views
9. Internet Explorer Layout Handling Memory Corruption Vulnerability // 23 views
10. Oracle Database Multiple Vulnerabilities // 17 views