PT-2008-3087 · Zyxel · Zyxel Prestige

Publicado

2008-03-26

·

Atualizado

2018-10-11

·

CVE-2008-1528

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ZyXEL Prestige routers, including P-660, P-661, and P-662 models, versions 3.40(AGD.2) through 3.40(AHQ.3)
Description The issue allows remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source. This can be demonstrated by making a request for (1) "RemMagSNMP.html", which discloses SNMP communities, or (2) "WLAN.html", which discloses WEP keys.
Recommendations For versions 3.40(AGD.2) through 3.40(AHQ.3), consider restricting access to the affected HTTP endpoints, such as "RemMagSNMP.html" and "WLAN.html", until a patch is available. As a temporary workaround, limit the disclosure of sensitive information, like SNMP communities and WEP keys, by restricting access to these endpoints.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1528

Produtos afetados

Zyxel Prestige