header-logo
Suggest Exploit
vendor:
Hot Standby Routing Protocol
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
399
CWE
Product Name: Hot Standby Routing Protocol
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2002-0231
CPE: cisco:hsrp
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
2002

Cisco Hot Standby Routing Protocol Denial of Service Vulnerability

A problem in the Cisco Hot Standby Routing Protocol (HSRP) makes it possible to deny service to users of network resources. By eavesdropping on HSRP management messages sent over the network, it is possible to create a spoofed message that will reroute all network traffic to a particular system. By doing so, it is possible to prevent traffic from entering or leaving that network.

Mitigation:

It is recommended that users of Cisco Hot Standby Routing Protocol upgrade to the latest version of the software, which is available from the vendor.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/2684/info

Hot Standby Routing Protocol is an Internet Protocol based routing protocol implemented by Cisco Systems. It is designed to offer traffic rerouting services to networks when one router within a pool ceases to operate, and users of the network segment aren't using ICMP Router Discovery Protocol to find the new router handling traffic for their segment.

A problem in the Cisco Hot Standby Routing Protocol (HSRP) makes it possible to deny service to users of network resources. By eavesdropping on HSRP management messages sent over the network, it is possible to create a spoofed message that will reroute all network traffic to a particular system. By doing so, it is possible to prevent traffic from entering or leaving that network.

This problem makes it possible for system local to the network to deny service to legitmate users of that network segment. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/20821.tgz