ID

VAR-200210-0081


CVE

CVE-2002-0949


TITLE

Telindus 1100 ADSL Router Administrator Password Disclosure Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200210-219

DESCRIPTION

Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router's password and other sensitive information in cleartext. The 1100 series routers are a broadband connectivity solution distributed by Telindus. Under some circumstances, a vulnerable Telindus router may leak sensitive information. When an attempt to connect to the router is made using the administrative software, the router sends the password to the client in plain text. This packet is sent via UDP. **The vendor has released firmware version 6.0.27, dated July 2002. Reports suggest that this firmware does not adequately protect against this vulnerability. The firmware is reported to use an encrypted UDP packet when connecting to the router. However, the firmware uses a weak encryption scheme and thus it is easily circumvented by an attacker. A design vulnerability in the Telindus 1100 series routers could allow a remote attacker to obtain administrator password information. Telindus 1100 series routers provide a management software, which can be downloaded from Telindus website for free, and can be used to remotely manage routers

Trust: 1.26

sources: NVD: CVE-2002-0949 // BID: 4946 // VULHUB: VHN-5338

AFFECTED PRODUCTS

vendor:telindusmodel:adsl routerscope:eqversion:1120

Trust: 1.9

vendor:telindusmodel:adsl routerscope:eqversion:1110

Trust: 1.9

vendor:telindusmodel:adsl router .21bscope:eqversion:11206.0

Trust: 0.3

sources: BID: 4946 // CNNVD: CNNVD-200210-219 // NVD: CVE-2002-0949

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-0949
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200210-219
value: HIGH

Trust: 0.6

VULHUB: VHN-5338
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-0949
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5338
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5338 // CNNVD: CNNVD-200210-219 // NVD: CVE-2002-0949

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-0949

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200210-219

TYPE

Design Error

Trust: 0.9

sources: BID: 4946 // CNNVD: CNNVD-200210-219

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-5338

EXTERNAL IDS

db:NVDid:CVE-2002-0949

Trust: 2.0

db:BIDid:4946

Trust: 2.0

db:CNNVDid:CNNVD-200210-219

Trust: 0.7

db:XFid:9277

Trust: 0.6

db:BUGTRAQid:20020605 SOME VULNERABILITIES IN THE TELINDUS 11XX ROUTER SERIES

Trust: 0.6

db:EXPLOIT-DBid:21513

Trust: 0.1

db:VULHUBid:VHN-5338

Trust: 0.1

sources: VULHUB: VHN-5338 // BID: 4946 // CNNVD: CNNVD-200210-219 // NVD: CVE-2002-0949

REFERENCES

url:http://www.securityfocus.com/bid/4946

Trust: 1.7

url:http://archives.neohapsis.com/archives/bugtraq/2002-06/0028.html

Trust: 1.7

url:http://www.iss.net/security_center/static/9277.php

Trust: 1.7

url:http://www.telindus.com/

Trust: 0.3

url:/archive/1/304670

Trust: 0.3

sources: VULHUB: VHN-5338 // BID: 4946 // CNNVD: CNNVD-200210-219 // NVD: CVE-2002-0949

CREDITS

finelli@ieee.org※>finelli@ieee.org</a>※ finelli@ieee.org

Trust: 0.6

sources: CNNVD: CNNVD-200210-219

SOURCES

db:VULHUBid:VHN-5338
db:BIDid:4946
db:CNNVDid:CNNVD-200210-219
db:NVDid:CVE-2002-0949

LAST UPDATE DATE

2024-08-14T14:29:36.484000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5338date:2008-09-05T00:00:00
db:BIDid:4946date:2009-07-11T13:56:00
db:CNNVDid:CNNVD-200210-219date:2005-10-20T00:00:00
db:NVDid:CVE-2002-0949date:2008-09-05T20:29:22.567

SOURCES RELEASE DATE

db:VULHUBid:VHN-5338date:2002-10-04T00:00:00
db:BIDid:4946date:2002-06-05T00:00:00
db:CNNVDid:CNNVD-200210-219date:2002-06-05T00:00:00
db:NVDid:CVE-2002-0949date:2002-10-04T04:00:00