Executive brief
The Routing Information Protocol version 1 (RIP v1), used by network devices to share information about how to direct internet traffic, lacks a mechanism to verify the identity of the sender. This allows an attacker to send fake routing information to a network, potentially misdirecting traffic or causing network instability. This could lead to unauthorized interception of data or disruption of network services.
Technical details
The Routing Information Protocol version 1 (RIP v1) does not support any form of authentication for routing updates. An unauthenticated remote attacker can send spoofed RIP response packets to a router, which the router will accept as legitimate updates to its routing table. This vulnerability allows for route poisoning, where an attacker can redirect traffic to a malicious host (Man-in-the-Middle) or create routing loops that lead to a Denial of Service (DoS). The issue is inherent to the RIP v1 specification; the primary mitigation is upgrading to RIP v2, which supports MD5 authentication, or using more secure routing protocols like OSPF.
Affected products
- Generic RIP v1 Protocol
Timeline
- 1997-07-01: disclosed: Initial publication date in NVD