PT-2001-2518 · Alcatel · Alcatel Speed Touch

Published

2001-04-10

·

Updated

2017-07-11

·

CVE-2001-1425

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Alcatel Speed Touch firmware KHDSAA.108 Alcatel Speed Touch firmware KHDSAA.132 through KHDSAA.134
Description The challenge-response authentication mechanism for the EXPERT user in Alcatel Speed Touch devices is susceptible to an issue that allows remote attackers to gain privileges. This is achieved by directly computing the response based on information provided by the device during the login process.
Recommendations For firmware KHDSAA.108, update to a version that addresses this issue. For firmware KHDSAA.132 through KHDSAA.134, update to a version that addresses this issue. As a temporary workaround, consider restricting access to the EXPERT user account until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1425

Affected Products

Alcatel Speed Touch