CVE-2013-4806

UnknownEPSS 1.92%

Last modified

CVE-2013-4806 is a vulnerability of currently unknown severity. The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.. EPSS estimates a 1.92% chance of exploitation in the next 30 days.

Description

The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

Metrics

EPSS Probability
1.92%

77.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Hp3com Router3012
Hp3com Router3018
Hp3com Router5012
Hp3com Router5232
Hp3com Router5642
Hp3com Router5642_taa
Hp3com Router5682
Hp5500-24g-4sfp Hi Switch With 2 Interface Slotsjg311a
Hp5500-24g-Poe Ei Switchjd378a
Hp5500-24g-Poe Si Switchjd371a
Hp5500-24g-Sfp Dc Ei Switchjd379a
Hp5500-24g-Sfp Ei Switchjd374a
Hp5500-24g Dc Ei Switchjd373a
Hp5500-24g Ei Switchjd377a
Hp5500-24g Si Switchjd369a
Hp5500-48g-Poe Ei Switchjd376a
Hp5500-48g-Poe Si Switchjd372a
Hp5500-48g Ei Switchjd375a
Hp5500-48g Si Switchjd370a
Hp5500g-24 Ei 10\/100\/1000 No Power Supply Unit Switchjf551a
Hp5500g-24 Ei Sfp No Power Supply Unit Switchjf553a
Hp5500g-48 Ei 10\/100\/1000 No Power Supply Unit Switchjf552a
HpH3c Ethernet Switchs5600-26c
HpH3c Ethernet Switchs5600-26c-pwr
HpH3c Ethernet Switchs5600-26f
HpH3c Ethernet Switchs5600-50c
HpH3c Ethernet Switchs5600-50c-pwr

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-4806?
The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
How severe is CVE-2013-4806?
Severity scoring for CVE-2013-4806 is pending analysis. The EPSS model estimates a 1.92% probability of exploitation in the next 30 days.
How do I fix CVE-2013-4806?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-4806?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST