Skip to content

qiupy123/CVE-2024-42861

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

CVE-2024-42861

The DOS attack against IEEE 802.1AS standard(gPTP protocol)

[CVE ID]
CVE-2024-42861

[PRODUCT]
IEEE 802.1AS standard

[VERSION]
IEEE 802.1AS-2020, IEEE 802.1AS-2010

[PROBLEM]
DOS attack

[DESCRIPTION]
When a port of a device with IEEE 802.1AS enabled receives two Pdelay_Req messages with different clockID, the time synchronization function of that port becomes disabled, leading to a denial of service attack.Attacker and the target are on the same Ethernet network. The attacker sends two Pdelay_Req messages with different ClockID to the target. Upon receiving these messages, the target's port will automatically terminate clock synchronization communication with the peer port, rendering the clock synchronization function of that port unavailable for a certain period of time. This DOS attack was successfully reproduced on linuxPTP(a software that implemnets the ptp and gptp protocols).

Releases

No releases published

Packages

No packages published