Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3698

Опубликовано: 17 мая 2016
Источник: redhat
CVSS2: 5.4
EPSS Низкий

Описание

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

It was found that libndp did not properly validate and check the origin of Neighbor Discovery Protocol (NDP) messages. An attacker on a non-local network could use this flaw to advertise a node as a router, allowing them to perform man-in-the-middle attacks on a connecting client, or disrupt the network connectivity of that client.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1329366libndp: denial of service due to insufficient validation of source of NDP messages

EPSS

Процентиль: 89%
0.03806
Низкий

5.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 10 лет назад

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

CVSS3: 8.1
nvd
больше 10 лет назад

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

CVSS3: 8.1
debian
больше 10 лет назад

libndp before 1.6, as used in NetworkManager, does not properly valida ...

CVSS3: 8.1
github
больше 4 лет назад

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

oracle-oval
больше 10 лет назад

ELSA-2016-1086: libndp security update (MODERATE)

EPSS

Процентиль: 89%
0.03806
Низкий

5.4 Medium

CVSS2