Executive brief
A vulnerability in Ascend and 3Com routers allows an attacker to remotely restart the device. These routers are critical networking components used to direct internet and corporate traffic. By triggering a reboot, an attacker can cause a temporary loss of connectivity, disrupting business operations and network availability.
Technical details
A denial of service vulnerability exists in the TCP/IP stack implementation of various Ascend and 3Com routers. The flaw is triggered when the device processes a TCP packet containing a zero-length TCP option. An unauthenticated remote attacker can exploit this by sending a specially crafted packet to the device, causing the router to crash and reboot. This results in a temporary denial of service for all network traffic passing through the affected hardware.
Affected products
- Ascend Routers
- 3Com Routers
Timeline
- 1997-12-01: disclosed: Initial publication date