ID

VAR-200212-0041


CVE

CVE-2002-2159


TITLE

LinkSys EtherFast Router Remote Management Activation Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2002-2861

DESCRIPTION

Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options are disabled, which allows remote attackers to gain access. Linksys EtherFast routers is a small four-port router designed to optimize the use of DSL or Cable connections.  This vulnerability is not present in other versions of firmware. EtherFast BEFSRU31 Router is prone to a remote security vulnerability. A remote attacker gains access

Trust: 1.8

sources: NVD: CVE-2002-2159 // CNVD: CNVD-2002-2861 // BID: 89532 // VULHUB: VHN-6542

AFFECTED PRODUCTS

vendor:linksysmodel:befsr41scope:eqversion:1.42.7

Trust: 1.6

vendor:linksysmodel:befsru31scope:eqversion:1.42.7

Trust: 1.6

vendor:linksysmodel:befsr11scope:eqversion:1.42.7

Trust: 1.6

vendor:nonemodel: - scope: - version: -

Trust: 0.6

vendor:linksysmodel:etherfast befsru31 routerscope:eqversion:1.42.7

Trust: 0.3

vendor:linksysmodel:etherfast befsr41 routerscope:eqversion:1.42.7

Trust: 0.3

vendor:linksysmodel:etherfast befsr11 routerscope:eqversion:1.42.7

Trust: 0.3

sources: CNVD: CNVD-2002-2861 // BID: 89532 // CNNVD: CNNVD-200212-842 // NVD: CVE-2002-2159

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-2159
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200212-842
value: CRITICAL

Trust: 0.6

VULHUB: VHN-6542
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-2159
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-6542
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-6542 // CNNVD: CNNVD-200212-842 // NVD: CVE-2002-2159

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-2159

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200212-842

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200212-842

EXTERNAL IDS

db:NVDid:CVE-2002-2159

Trust: 2.6

db:BIDid:4987

Trust: 2.0

db:CNNVDid:CNNVD-200212-842

Trust: 0.7

db:CNVDid:CNVD-2002-2861

Trust: 0.6

db:XFid:9330

Trust: 0.6

db:BIDid:89532

Trust: 0.4

db:VULHUBid:VHN-6542

Trust: 0.1

sources: CNVD: CNVD-2002-2861 // VULHUB: VHN-6542 // BID: 89532 // CNNVD: CNNVD-200212-842 // NVD: CVE-2002-2159

REFERENCES

url:http://www.securityfocus.com/bid/4987

Trust: 2.0

url:http://www.securiteam.com/securitynews/5op022k7ge.html

Trust: 2.0

url:http://www.iss.net/security_center/static/9330.php

Trust: 2.0

sources: VULHUB: VHN-6542 // BID: 89532 // CNNVD: CNNVD-200212-842 // NVD: CVE-2002-2159

CREDITS

Unknown

Trust: 0.3

sources: BID: 89532

SOURCES

db:CNVDid:CNVD-2002-2861
db:VULHUBid:VHN-6542
db:BIDid:89532
db:CNNVDid:CNNVD-200212-842
db:NVDid:CVE-2002-2159

LAST UPDATE DATE

2024-08-14T14:42:24.217000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2002-2861date:2002-06-14T00:00:00
db:VULHUBid:VHN-6542date:2017-07-12T00:00:00
db:BIDid:89532date:2002-12-31T00:00:00
db:CNNVDid:CNNVD-200212-842date:2006-02-01T00:00:00
db:NVDid:CVE-2002-2159date:2017-07-12T01:29:00.847

SOURCES RELEASE DATE

db:CNVDid:CNVD-2002-2861date:2002-06-11T00:00:00
db:VULHUBid:VHN-6542date:2002-12-31T00:00:00
db:BIDid:89532date:2002-12-31T00:00:00
db:CNNVDid:CNNVD-200212-842date:2002-12-31T00:00:00
db:NVDid:CVE-2002-2159date:2002-12-31T05:00:00