Cisco Catalyst 5000 Series Frame STP Port Broadcast DoS (CSCdt62732)

This script is (C) 2002-2014 Tenable Network Security, Inc.


Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

When an 802.1x (IEEE standard for port based network access control)
frame is received by an affected Catalyst 5000 series switch on a STP
(Spanning Tree Protocol) blocked port it is forwarded in that VLAN
(Virtual Local Area Network) instead of being dropped. This causes a
performance impacting 802.1x frames network storm in that part of the
network, which is made up of the affected Catalyst 5000 series
switches. This network storm only subsides when the source of the
802.1x frames is removed or one of the workarounds in the workaround
section is applied.

This vulnerability is documented as Cisco bug ID CSCdt62732.

Solution :

http://www.nessus.org/u?e0c2952e

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 3.7
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: CISCO

Nessus Plugin ID: 10980 (CSCdt62732.nasl)

Bugtraq ID: 2604

CVE ID: CVE-2001-0429