CVE-2013-7312
The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
Published:Jan 23, 2014
Last Modified:Apr 11, 2025
EPS:Jan 23, 2014
EPSS Score:0.0031
CVSS Score:5.4
Affected Products
Vendor
Product
Action
Vendor
Enterasys
Product
C5
Enterasys
C5
Vendor
Enterasys
Product
G3
Enterasys
G3
Vendor
Enterasys
Product
K10
Enterasys
K10
Vendor
Enterasys
Product
K6
Enterasys
K6
Vendor
Enterasys
Product
S130
Enterasys
S130
Vendor
Enterasys
Product
S140
Enterasys
S140
Vendor
Enterasys
Product
S150
Enterasys
S150
Vendor
Enterasys
Product
S155
Enterasys
S155
Vendor
Enterasys
Product
S180
Enterasys
S180
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
