CVE-2013-4806: HP 3com Router
High severity, CVSS 7.0. EPSS: 1.9% chance of exploitation in the next 30 days.
The OSPF implementation on HP JD9##A routers; HP J4###A, J484#B, J8###A, JD3##A, JE###A, and JF55#A switches; HP 3COM routers and switches; and HP H3C routers and switches does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote authenticated users to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
Affected products
- HP 3com Router: version 3012 only; version 3018 only; version 5012 only; version 5232 only; version 5642 only; version 5642_taa only; …
- HP 5500-24g-4sfp Hi Switch With 2 Interface Slots: version jg311a only
- HP 5500-24g-Poe Ei Switch: version jd378a only
- HP 5500-24g-Poe Si Switch: version jd371a only
- HP 5500-24g-Sfp DC Ei Switch: version jd379a only
- HP 5500-24g-Sfp Ei Switch: version jd374a only
- HP 5500-24g DC Ei Switch: version jd373a only
- HP 5500-24g Ei Switch: version jd377a only
- HP 5500-24g Si Switch: version jd369a only
- HP 5500-48g-Poe Ei Switch: version jd376a only
- HP 5500-48g-Poe Si Switch: version jd372a only
- HP 5500-48g Ei Switch: version jd375a only
- HP 5500-48g Si Switch: version jd370a only
- HP 5500g-24 Ei 10/100/1000 No Power Supply Unit Switch: version jf551a only
- HP 5500g-24 Ei Sfp No Power Supply Unit Switch: version jf553a only
- HP 5500g-48 Ei 10/100/1000 No Power Supply Unit Switch: version jf552a only
- HP h3c Ethernet Switch: version s5600-26c only; version s5600-26c-pwr only; version s5600-26f only; version s5600-50c only; version s5600-50c-pwr only
Published 2013-08-12. Last modified 2026-06-16.