SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-4441

The PVLAN protocol allows remote attackers to bypass network segmentation and spoof PVLAN traffic via a PVLAN message with a target MAC address that is set to a gateway router, which causes the packet to be sent to the router, where the source MAC is…

MEDIUM 5.0EPSS 1.61%

Does this matter?

Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.

Description

The PVLAN protocol allows remote attackers to bypass network segmentation and spoof PVLAN traffic via a PVLAN message with a target MAC address that is set to a gateway router, which causes the packet to be sent to the router, where the source MAC is modified, aka "Modification of the MAC spoofing PVLAN jumping attack," as demonstrated by pvlan.c.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.61% probability · 75th percentile
CISA KEV
Not listed
Affected
pvlan protocol/pvlan protocol
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.