CVE-2013-7308

D-Link DES-3810-28 Firmware R2.20.B017 - Denial of Service via Duplicate LSA Link State ID

Title source: llm
STIX 2.1

Description

The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2.20.B017 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/BLUU-985QRV
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/229804

Scores

EPSS 0.0008
EPSS Percentile 22.9%

Details

Status published
Products (2)
dlink/des-3810-28
dlink/des-3810-28_firmware r2.20.b017
Published Jan 23, 2014
Tracked Since Feb 18, 2026