ID

VAR-200307-0053


TITLE

Asus AAM6000EV ADSL Router Information Disclosure Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2003-2157

DESCRIPTION

The Asus AAM6000EV is an ADSL router. Asus AAM6000EV ADSL files with sensitive information can be accessed directly, and intranet users can use this vulnerability to obtain username and password information. If the WEB server embedded in the Asus AAM6000EV ADSL router is enabled, users on any local network can obtain some plain text username and password information by accessing the /userdata file. It is possible to request files from the built-in Web server that contain information such as usernames, passwords and other configuration information

Trust: 0.81

sources: CNVD: CNVD-2003-2157 // BID: 8183

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2003-2157

AFFECTED PRODUCTS

vendor:asusmodel:aam6330bi nullscope: - version: -

Trust: 0.6

vendor:asusmodel:aam6330biscope: - version: -

Trust: 0.3

vendor:asusmodel:aam6000evscope: - version: -

Trust: 0.3

sources: CNVD: CNVD-2003-2157 // BID: 8183

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2003-2157
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2003-2157
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2003-2157

THREAT TYPE

network

Trust: 0.3

sources: BID: 8183

TYPE

Access Validation Error

Trust: 0.3

sources: BID: 8183

EXTERNAL IDS

db:BIDid:8183

Trust: 0.9

db:CNVDid:CNVD-2003-2157

Trust: 0.6

sources: CNVD: CNVD-2003-2157 // BID: 8183

REFERENCES

url:http://marc.theaimsgroup.com/?l=bugtraq&m=105821398921956&w=2

Trust: 0.6

url:/archive/1/329008

Trust: 0.3

url:/archive/1/329183

Trust: 0.3

sources: CNVD: CNVD-2003-2157 // BID: 8183

CREDITS

Reported by "cw" <security@fidei.co.uk>. Independent discovery reported by Andrew Hodgson <andrew@hodgsonfamily.org>.

Trust: 0.3

sources: BID: 8183

SOURCES

db:CNVDid:CNVD-2003-2157
db:BIDid:8183

LAST UPDATE DATE

2022-05-17T01:47:38.216000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2003-2157date:2003-07-14T00:00:00
db:BIDid:8183date:2003-07-14T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2003-2157date:2003-07-14T00:00:00
db:BIDid:8183date:2003-07-14T00:00:00