ID

VAR-200304-0101


CVE

CVE-2002-1431


TITLE

Belkin F5D5230-4 Inside the router Web Traffic Origin Obfuscation Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200304-095

DESCRIPTION

Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attackers to hide which host is being used to access the web server. The Belkin F5D5230-4 4-Port Cable/DSL Gateway Router is a hardware router for a home or small office. When a request for a service that has been remapped to the internal network is made via the WAN interface, and the origin is the internal network, the router reacts unpredictably. The origin address is rewritten as the IP address of the external interface by the device before being passed to the internal network. Upon receiving a request of this nature, the device will rewrite all future requests for services mapped to the WAN network, reporting their origin as that of the WAN interface. This is known to be an issue for requests for port 80, if port 80 has been remapped to a host within the internal network. This may potentially be exploited to obscure the origin of attacks against a webserver in the internal network

Trust: 1.26

sources: NVD: CVE-2002-1431 // BID: 4982 // VULHUB: VHN-5816

AFFECTED PRODUCTS

vendor:belkinmodel:f5d5230-4 4-port cable dsl gateway routerscope:eqversion:1.20.000

Trust: 1.6

vendor:belkinmodel:f5d5230-4scope: - version: -

Trust: 0.3

sources: BID: 4982 // CNNVD: CNNVD-200304-095 // NVD: CVE-2002-1431

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1431
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200304-095
value: HIGH

Trust: 0.6

VULHUB: VHN-5816
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-1431
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5816
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5816 // CNNVD: CNNVD-200304-095 // NVD: CVE-2002-1431

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1431

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200304-095

TYPE

Design Error

Trust: 0.9

sources: BID: 4982 // CNNVD: CNNVD-200304-095

EXTERNAL IDS

db:NVDid:CVE-2002-1431

Trust: 2.0

db:BIDid:4982

Trust: 2.0

db:CNNVDid:CNNVD-200304-095

Trust: 0.7

db:XFid:9324

Trust: 0.6

db:BUGTRAQid:20020609 PROBLEM WITH IP REPORTING - BELKIN CABLE/DSL ROUTER

Trust: 0.6

db:VULHUBid:VHN-5816

Trust: 0.1

sources: VULHUB: VHN-5816 // BID: 4982 // CNNVD: CNNVD-200304-095 // NVD: CVE-2002-1431

REFERENCES

url:http://www.securityfocus.com/bid/4982

Trust: 1.7

url:http://online.securityfocus.com/archive/1/276256

Trust: 1.7

url:http://www.iss.net/security_center/static/9324.php

Trust: 1.7

url:http://catalog.belkin.com/iwcatproductpage.process?merchant_id=&section_id=2094&pcount=&product_id=113464&section.section_path=%2froot%2fnetworki%2e%2e%2endcables%2fcabledsl%2e%2e%2eyrouters%2f

Trust: 0.3

sources: VULHUB: VHN-5816 // BID: 4982 // CNNVD: CNNVD-200304-095 // NVD: CVE-2002-1431

CREDITS

Reported by M Freitas <freitasm@mailcity.com>.

Trust: 0.9

sources: BID: 4982 // CNNVD: CNNVD-200304-095

SOURCES

db:VULHUBid:VHN-5816
db:BIDid:4982
db:CNNVDid:CNNVD-200304-095
db:NVDid:CVE-2002-1431

LAST UPDATE DATE

2024-08-14T14:48:13.541000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5816date:2008-09-05T00:00:00
db:BIDid:4982date:2009-07-11T13:56:00
db:CNNVDid:CNNVD-200304-095date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1431date:2008-09-05T20:30:35.030

SOURCES RELEASE DATE

db:VULHUBid:VHN-5816date:2003-04-11T00:00:00
db:BIDid:4982date:2002-06-10T00:00:00
db:CNNVDid:CNNVD-200304-095date:2003-04-11T00:00:00
db:NVDid:CVE-2002-1431date:2003-04-11T04:00:00