ID

VAR-200803-0064


CVE

CVE-2008-1268


TITLE

Linksys WRT54G 7 On the router FTP On the server FTP Session establishment vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2008-004207

DESCRIPTION

The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to establish an FTP session by sending an arbitrary username and password. WRT54G v1.0 is prone to a remote security vulnerability

Trust: 1.98

sources: NVD: CVE-2008-1268 // JVNDB: JVNDB-2008-004207 // BID: 85076 // VULHUB: VHN-31393

AFFECTED PRODUCTS

vendor:linksysmodel:wrt54gscope:eqversion:7

Trust: 1.6

vendor:cisco linksysmodel:wrt54gscope:eqversion:7.00.1

Trust: 0.8

vendor:linksysmodel:wrt54gscope:eqversion:v1.077.00.1

Trust: 0.3

sources: BID: 85076 // JVNDB: JVNDB-2008-004207 // CNNVD: CNNVD-200803-146 // NVD: CVE-2008-1268

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-1268
value: HIGH

Trust: 1.0

NVD: CVE-2008-1268
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200803-146
value: CRITICAL

Trust: 0.6

VULHUB: VHN-31393
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2008-1268
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-31393
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-31393 // JVNDB: JVNDB-2008-004207 // CNNVD: CNNVD-200803-146 // NVD: CVE-2008-1268

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-31393 // JVNDB: JVNDB-2008-004207 // NVD: CVE-2008-1268

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200803-146

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-200803-146

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-004207

PATCH

title:Linksysurl:http://home.cisco.com/en-apac/home

Trust: 0.8

sources: JVNDB: JVNDB-2008-004207

EXTERNAL IDS

db:NVDid:CVE-2008-1268

Trust: 2.8

db:XFid:41119

Trust: 0.9

db:JVNDBid:JVNDB-2008-004207

Trust: 0.8

db:CNNVDid:CNNVD-200803-146

Trust: 0.7

db:BUGTRAQid:20080301 THE ROUTER HACKING CHALLENGE IS OVER!

Trust: 0.6

db:XFid:54

Trust: 0.6

db:BIDid:85076

Trust: 0.4

db:VULHUBid:VHN-31393

Trust: 0.1

sources: VULHUB: VHN-31393 // BID: 85076 // JVNDB: JVNDB-2008-004207 // CNNVD: CNNVD-200803-146 // NVD: CVE-2008-1268

REFERENCES

url:http://swbae.egloos.com/1701135

Trust: 2.0

url:http://www.gnucitizen.org/projects/router-hacking-challenge/

Trust: 2.0

url:http://www.securityfocus.com/archive/1/489009/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/41119

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/41119

Trust: 0.9

url:http://www.securityfocus.com/archive/1/archive/1/489009/100/0/threaded

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-1268

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-1268

Trust: 0.8

sources: VULHUB: VHN-31393 // BID: 85076 // JVNDB: JVNDB-2008-004207 // CNNVD: CNNVD-200803-146 // NVD: CVE-2008-1268

CREDITS

Unknown

Trust: 0.3

sources: BID: 85076

SOURCES

db:VULHUBid:VHN-31393
db:BIDid:85076
db:JVNDBid:JVNDB-2008-004207
db:CNNVDid:CNNVD-200803-146
db:NVDid:CVE-2008-1268

LAST UPDATE DATE

2024-11-23T21:19:05.475000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-31393date:2018-10-11T00:00:00
db:BIDid:85076date:2008-03-10T00:00:00
db:JVNDBid:JVNDB-2008-004207date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200803-146date:2008-09-05T00:00:00
db:NVDid:CVE-2008-1268date:2024-11-21T00:44:07.500

SOURCES RELEASE DATE

db:VULHUBid:VHN-31393date:2008-03-10T00:00:00
db:BIDid:85076date:2008-03-10T00:00:00
db:JVNDBid:JVNDB-2008-004207date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200803-146date:2008-03-10T00:00:00
db:NVDid:CVE-2008-1268date:2008-03-10T17:44:00