Secunia Logo  


Secunia PSI WorldMap
 
Nortel Networks Products ICMP Handling Vulnerabilities
Secunia Advisory: SA15761
Release Date: 2005-07-14
Popularity: 7,976 views

Critical:
Less critical
Impact: DoS
Where: From remote
Solution Status: Vendor Workaround

OS:Nortel Access Stack Node (ASN) Router
Nortel Advanced Remote Node (ARN) Router (formerly Passport)
Nortel Application Switches (formerly Alteon)
Nortel Backbone Concentrator Node (BCN) Router
Nortel Backbone Link Node (BLN) Router
Nortel Ethernet Routing Switch 5510 (formerly BayStack)
Nortel Ethernet Routing Switch 5520 (formerly BayStack)
Nortel Ethernet Routing Switch 8600 (formerly Passport)
Nortel Ethernet Switch 420-24T (formerly BayStack)
Nortel Ethernet Switch 425 (formerly BayStack)
Nortel Ethernet Switch 470 (formerly BayStack)
Nortel Multiprotocol Router 2430 (formerly Passport)
Nortel Multiprotocol Router 5430 (formerly Passport)
Nortel Multiservice Access Switch 4400 Series (formerly Passport)
Nortel Multiservice Switch 15000 (formerly Passport)
Nortel Multiservice Switch 20000 (formerly Passport)
Nortel Multiservice Switch 6400 (formerly Passport)
Nortel Multiservice Switch 7400 (formerly Passport)
Nortel Passport 1150 Routing Switch
Nortel Services Edge Router 5500 (formerly Shasta)
Nortel VPN Routers

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Application Switch (Alteon Family):
The vendor recommends using the data port instead of the management port for management traffic or connect the management port to a secured segment of the network.

BayStack family of products:
The vendor has reportedly issued a patch.

VPN Router:
The vendor recommends limiting exposure by disabling the few allowed TCP protocols permitted on the public side if they are not in use (PPTP, HTTPS, SSL, and LDAP).

Ethernet Routing Switch (Passport 8600 Routing Switch):
Update to release 3.5.10.0 or 3.7.7.0.

Multiservice Access Switch 4400 (formerly Passport 4400):
Update to release 4.3.1.7.3.0 , 5.2.0.11.9.0, or 4.0.4.30.8.0.

Ethernet Routing Switch (Passport Family 1100/1150/1200/1250):
A fix is reportedly available.

Services Edge Router (Shasta Family):
The vendor recommends configuring a security IP policy protecting against these types of attacks.

Multiprotocol Router Family:
Patches are available for the 15.6, 15.5, 15.4, and 14.0 release streams.

Original Advisory:
Nortel Networks:
http://www130.nortelnetworks.com/cgi-...1&subtype=&DocumentOID=326515

Other References:
SA14904:
http://secunia.com/advisories/14904/

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

11th Nov, 2009
New advisories: 18
New vulnerabilities: 40
Updated advisories: 39

Less // 212 views
Fedora update for dhcp
Moderately // 221 views
Fedora update for ocaml-camlimages
Moderately // 215 views
Fedora update for libvorbis
Less // 210 views
Fedora update for wordpress-mu
Highly // 281 views
Red Hat update for java-1.5.0-sun

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 46 views
2. Microsoft Windows Win32k Kernel-Mode Driver Multiple Vulnerabilities // 28 views
3. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 28 views
4. Adobe Flash Player Multiple Vulnerabilities // 25 views
5. Red Hat update for 4Suite // 20 views
6. Fedora update for ocaml-camlimages // 20 views
7. Fedora update for dhcp // 20 views
8. Adobe Reader/Acrobat Multiple Vulnerabilities // 19 views
9. Citrix XenApp Online Plug-in / Receiver Certificate Spoofing Vulnerability // 17 views
10. Citrix Secure Gateway TLS Session Renegotiation Plaintext Injection // 17 views