SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-2476

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin…

HIGH 9.3EPSS 7.42%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (7.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
7.42% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
force10/ftos · freebsd/freebsd · juniper/jnos · netbsd/netbsd · openbsd/openbsd · windriver/vxworks
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.