vendor:
Windows, Solaris
by:
L0pht (LHI)
7.5
CVSS
HIGH
Spoofing
284
CWE
Product Name: Windows, Solaris
Affected Version From: Microsoft Windows95 (w/winsock2), Windows95b, Windows98, Windows98se, and Windows2000
Affected Version To: Solaris2.6
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2002
IRDP Router Discovery Protocol Vulnerability
The ICMP Router Discovery Protocol (IRDP) comes enabled by default on DHCP clients that are running Microsoft Windows95 (w/winsock2), Windows95b, Windows98, Windows98se, and Windows2000 machines. By spoofing IRDP Router Advertisements, an attacker can remotely add default route entries on a remote system. The default route entry added by the attacker will be preferred over the default route obtained from the DHCP server. This results in higher susceptibility to denial of service, passive snooping and man in the middle attacks.
Mitigation:
Disable IRDP on the system or configure firewall rules to block incoming IRDP packets.