PT-2009-6531 · Internet Initiative Japan · Seil/B1

Published

2009-12-23

·

Updated

2010-01-06

·

CVE-2009-4409

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Internet Initiative Japan SEIL/B1 firmware versions 1.00 through 2.52
Description The issue concerns the PPP Access Concentrator function in the firmware, specifically the CHAP and MS-CHAP-V2 authentication capabilities. These capabilities use the same challenge for each authentication attempt, allowing remote attackers to bypass authentication via a replay attack.
Recommendations For versions 1.00 through 2.52, consider disabling the CHAP and MS-CHAP-V2 authentication capabilities until a patch is available. Restrict access to the PPP Access Concentrator function to minimize the risk of exploitation. Avoid using the same challenge for each authentication attempt to prevent replay attacks. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4409

Affected Products

Seil/B1