The DOS attack against IEEE 802.1AS standard(gPTP protocol)
[CVE ID]
CVE-2024-42861
[PRODUCT]
IEEE 802.1AS standard
[VERSION]
IEEE 802.1AS-2020, IEEE 802.1AS-2010
[PROBLEM]
DOS attack
[DESCRIPTION]
When a port of a device with IEEE 802.1AS enabled receives two Pdelay_Req messages with different clockID, the time synchronization function of that port becomes disabled, leading to a denial of service attack.Attacker and the target are on the same Ethernet network. The attacker sends two Pdelay_Req messages with different ClockID to the target. Upon receiving these messages, the target's port will automatically terminate clock synchronization communication with the peer port, rendering the clock synchronization function of that port unavailable for a certain period of time. This DOS attack was successfully reproduced on linuxPTP(a software that implemnets the ptp and gptp protocols).
-
Notifications
You must be signed in to change notification settings - Fork 0
qiupy123/CVE-2024-42861
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
the
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published