Nortel issues patch for router VPN flaw
The vulnerability affects several models in the Nortel VPN Router line
June 1, 2005 12:00 PM ETIDG News Service -
Nortel Networks Corp. is offering a fix for a vulnerability that could let an attacker crash a virtual private network (VPN) router with a single malformed packet.
The denial-of-service vulnerability, reported by U.K.-based Internet security testing company NTA Monitor Ltd., affects several models in the Nortel VPN Router line, formerly known as the Nortel Contivity line. NTA characterized the vulnerability as serious, and Nortel gave it "major priority" status.
An attacker could cause the routers to reboot or to crash by sending a single Internet Key Exchange (IKE) packet with a malformed Internet Security Association and Key Management Protocol header, according to an advisory on NTA Monitor's Web site. In testing, most routers restarted -- which takes about five minutes -- and some required manual intervention to be restarted, NTA said. The routers don't log any information about the packet, probably because they crash before having a chance to log it, according to the advisory.
Normally, it is not possible to prevent the malformed packet from reaching the router, NTA warned. An attacker could forge the packet's source or take other steps to prevent the router from blocking the packet, according to the company. The packet looks very similar to a normal IKE packet.
NTA did not provide details of the malformed packet out of concern that it could be exploited by an attacker before the majority of Nortel users have patched their routers.
The vulnerability affects all products in the VPN Router 600, 1000, 2000, 4000 and 5000 lines. Nortel recommends upgrading those systems to Version 5.05.200 of the software, which was released May 16, or to install the patched versions of the Version 4.76, 4.85, 4.90 or 5.00 software, which will be made available this month, according to a Nortel security bulletin.
NTA said it found the problem March 3 while doing a VPN test for a customer, then notified Nortel, which provided the fix.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...
Security Configuration Management
In this web video, follow along with Jim Hansen, Senior Product Manager with Big Fix, as he explains why Security Configuration Management is...
ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
2007 Gartner Magic Quadrant Report
Riverbed positioned in Leaders Quadrant of Gartner Magic Quadrant for WAN Optimization Controllers. Analyzing strengths vs. cautions, Gartner helps organizations looking to acquire...
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
Business Value of Performance IDC Whitepaper
Are you looking for a comprehensive solution that addresses insufficient or congested bandwidth, impaired application performance, slow remote backup and replication or obstacles...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Subscribe to Computerworld
