Title: IEEE 802.1q Unauthorized VLAN Traversal Weakness
Severity: MODERATE
Description:
802.1q is a protocol by the IEEE used to support virtual LAN networks (VLANs). The protocol specification alters the standard Ethernet header to include a VLAN identification number.
The 802.1q standard is susceptible to issues that allow attackers to send and receive packets from one VLAN to another without authorization.
By spoofing various Ethernet frame fields such as the source or destination MAC addresses, IP addresses, and VLAN tags, attackers may cause packets to traverse from one VLAN to another, and possibly back again. Attackers may also add multiple VLAN tags to packets to cause multiple routers to decapsulate the packets in unexpected ways, aiding the attacker in traversing VLANs.
This issue allows attackers to traverse from one VLAN to another in an unauthorized fashion. As some users may utilize VLANs to segregate network segments containing differing security properties, this may have various consequences.
This issue may be exacerbated by utilizing attacker-controlled external network hosts to bounce packets between VLANs.
Affected Products:
- Cisco Catalyst WS-C2924M-XL
- Cisco IOS 11.2.8SA5
- IEEE 802.1q
References:
- Cisco Systems: Cisco Product Security Incident Response
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.