Executive brief
A vulnerability in Avaya's networking software for Virtual Services Platforms could allow an attacker to gain unauthorized access to network traffic. This software is used to manage high-performance data center and campus networks. An exploit could lead to the exposure of sensitive data or unauthorized control over network segments, potentially disrupting business operations.
Technical details
The vulnerability exists in the way Avaya VOSS handles VLAN and Intermediate System to Intermediate System (I-SIS) indexes within the Fabric Connect architecture. By sending specially crafted Ethernet frames, a remote attacker can bypass intended traffic isolation and gain unauthorized access to network segments. This is categorized as a data processing error (CWE-19) related to Shortest Path Bridging (SPB) traffic traversal. The flaw allows for complete compromise of confidentiality, integrity, and availability without requiring authentication or user interaction. Patches were released in versions 4.2.3.0 and 5.0.1.0.
Affected products
- Avaya VSP Operating System Software (VOSS) Before 4.2.3.0, 5.x before 5.0.1.0
Timeline
- 2016-07-27: disclosed: Initial discovery/reporting period based on CVE ID and external references
- 2017-01-23: advisory: NVD publication date