Executive brief
Ascend MAX and Pipeline routers are susceptible to a flaw that allows remote attackers to crash or disable the device. By sending a specially crafted data packet to a specific network port used by the Java Configurator tool, an attacker can disrupt internet connectivity and network operations. This results in a denial of service, preventing legitimate users and systems from communicating through the affected hardware.
Technical details
A denial of service vulnerability exists in the Ascend MAX and Pipeline router firmware. The issue is triggered by sending a malformed packet to the 'discard' port (typically used by the Java Configurator tool). An unauthenticated remote attacker can exploit this vulnerability to cause the device to hang or reboot, leading to a loss of availability. The vulnerability is reachable over the network without user interaction. While the original vendor advisory is no longer available, the flaw is historically documented as affecting the handling of specific malformed inputs on management-related ports.
Affected products
- Ascend MAX Router
- Ascend Pipeline Router
Timeline
- 1998-03-16: disclosed