PT-2001-2518 · Alcatel · Alcatel Speed Touch

Publicado

2001-04-10

·

Atualizado

2017-07-11

·

CVE-2001-1425

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Alcatel Speed Touch firmware KHDSAA.108 Alcatel Speed Touch firmware KHDSAA.132 through KHDSAA.134
Description The challenge-response authentication mechanism for the EXPERT user in Alcatel Speed Touch devices is susceptible to an issue that allows remote attackers to gain privileges. This is achieved by directly computing the response based on information provided by the device during the login process.
Recommendations For firmware KHDSAA.108, update to a version that addresses this issue. For firmware KHDSAA.132 through KHDSAA.134, update to a version that addresses this issue. As a temporary workaround, consider restricting access to the EXPERT user account until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1425

Produtos afetados

Alcatel Speed Touch