When the authentication check at nhrp_packet.c:817-832 fails, the daemon sends an Error Indication reply via nhrp_packet_send_error(). The error reply goes through nhrp_packet_route_and_send() which unconditionally inserts the interface's auth_token (plaintext shared secret) into the Authentication extension at lines 1105-1112.
The error reply is routed to src_protocol_address of the attacker's packet via peer-table lookup. If a peer entry exists for the attacker's claimed protocol address (from spoke registration, static map, or dynamic-map), the reply — containing the plaintext secret — is sent to that peer's NBMA address
Description
Description
Details
Details
- Version
- -
- Is it a breaking change?
- Unspecified (possibly destroys the router)
- Issue type
- Security vulnerability