2008-4404 | IBM zSeries IPv6 Neighbor Discovery input validation (BID-31529 / XFDB-45601)

A vulnerability was found in IBM zSeries (unknown version). It has been rated as critical. This issue affects an unknown code block of the component IPv6 Neighbor Discovery. The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-20. Impacted is confidentiality, integrity, and availability. The summary by CVE is:

The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.

The bug was discovered 10/02/2008. The weakness was published 10/03/2008 as confirmed advisory (CERT.org). It is possible to read the advisory at kb.cert.org. The identification of this vulnerability is CVE-2008-4404 since 10/03/2008. The exploitation is known to be easy. The attack may be initiated remotely. No form of authentication is needed for a successful exploitation. The technical details are unknown and an exploit is not publicly available.

The vulnerability was handled as a non-public zero-day exploit for at least 1 days. During that time the estimated underground price was around $5k-$25k. The vulnerability scanner Nessus provides a plugin with the ID 35642 (HP-UX PHNE_37897 : HP-UX Running IPv6, Remote Denial of Service (DoS) and Unauthorized Access (HPSBUX02407 SSRT080107 rev.1)), which helps to determine the existence of the flaw in a target environment. It is assigned to the family HP-UX Local Security Checks and running in the context local. The commercial vulnerability scanner Qualys is able to test this issue with plugin 116191 (HP-UX Running IPv6, Remote Denial of Service Vulnerability (HPSBUX02407)).

Applying a patch is able to eliminate this problem. A possible mitigation has been published 5 months after the disclosure of the vulnerability.

The vulnerability is also documented in the databases at SecurityFocus (BID 31529), X-Force (45601), Vulnerability Center (SBV-19674) and Tenable (35642). Similar entries are available at 46293 and 44311.



Class: Privilege escalation
Local: No
Remote: Yes

Nessus ID: 35642
Nessus Name: HP-UX PHNE_37897 : HP-UX Running IPv6, Remote Denial of Service (DoS) and Unauthorized Access (HPSBUX02407 SSRT080107 rev.1)
OpenVAS ID: 835194
OpenVAS Name: HP-UX Update for NFS/ONCplus HPSBUX02375
Recommended: Patch
Patch: kb.cert.org

Advisory: kb.cert.org
Status: Confirmed

CVE: CVE-2008-4404

SecurityFocus: 31529
X-Force: 45601
Vulnerability Center: 19674 – IBM zSeries Servers IPv6 NDP Implementation Remote DoS and Network Traffic Disclosure Vulnerability, High
OSVDB: 48991 – CVE-2008-4404 – IBM – ZSeries – Denial-Of-Service Issue

Created: 03/17/2015 16:11
Updated: 08/02/2021 10:32
