Secunia Logo
 
HP ProCurve 5300xl Series RPC Traffic Denial of Service
Secunia Advisory: SA10319
Release Date: 2003-12-01
Popularity: 6,365 views

Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch

OS:HP ProCurve 5300xl Series

Subscribe: Instant alerts on relevant vulnerabilities


Description:
HP has reported a vulnerability in ProCurve 5300xl series switches, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an unspecified error when handling RPC traffic, which may cause performance to degrade. This behaviour can e.g. be triggered by the Welchia and Blaster worms.

The vulnerability affects HP ProCurve Switch 5304XL (J4850A), 5348XL (J4849A), 5372XL (J4848A), and 5308XL (J4819A).

Solution:
Update switch software to E.07.40 or subsequent.
http://www.hp.com/rnd/software/switches.htm

Original Advisory:
SSRT3647 ProCurve 5300 series and RPC worms:
http://www4.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMI0311-006


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Apple iPhone / iPod touch Multiple Vulnerabilities // 44 views
2. Sun Java JDK / JRE Multiple Vulnerabilities // 31 views
3. phpBB Avatar Script Insertion Vulnerability // 27 views
4. Microsoft XML Core Services Multiple Vulnerabilities // 23 views
5. Avaya CMS Solaris "sadmind" Buffer Overflow Vulnerability // 22 views
6. phpJobScheduler "installed_config_file" File Inclusion Vulnerabilities // 21 views
7. phpBB Avatar Functions Information Disclosure and Deletion // 21 views
8. Symantec Backup Exec for Windows Servers Multiple Vulnerabilities // 21 views
9. IBM Workplace Web Content Management Cross-Site Scripting Vulnerabilities // 20 views
10. phpBB Cross Site Scripting and Unspecified Vulnerabilities // 20 views