|
OfficeConnect Wireless 11g Access Point Information Disclosure
|
|
Secunia Advisory:
|
SA13942
|
|
|
Release Date:
|
2005-01-20
|
|
Last Update:
|
2005-04-04
|
|
Popularity:
|
9,637 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Exposure of system information Exposure of sensitive information
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | 3Com ADSL 11g Wireless Router (3CRADSL72) 3Com OfficeConnect Wireless 11g Access Point (3CRWE454G72)
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2005-0112
|
|
Description: A vulnerability has been reported in 3Com OfficeConnect Wireless 11g Access Point, which can be exploited by malicious people to gain knowledge of sensitive information.
The vulnerability is caused due to an access control error allowing anyone to access certain hidden pages via the web interface.
Examples:
/main/config.bin
/main/profile.wlp?PN=ggg
/main/event.logs
Successful exploitation discloses sensitive device information including the administrator's username and password.
Solution: For 3Com OfficeConnect Wireless 11g Access Point (3CRWE454G72) update to firmware release 1.03.07A:
http://webprd1.3com.com/swd/jsp/user/index.jsp?id=OCWAPG1
For 3Com ADSL 11g Wireless Router (3CRADSL72) this has reportedly been fixed in firmware release 1.10.
Provided and/or discovered by: Originally discovered by:
Patrik, cqure.net.
Lostmon and vIOsOnE found that this also affects 3Com ADSL 11g Wireless Router (3CRADSL72).
Changelog: 2005-01-21: Added additional information provided by iDEFENSE. Updated credits.
2005-04-04: Added 3Com ADSL 11g Wireless Router (3CRADSL72) as vulnerable.
Original Advisory: iDEFENSE:
http://www.idefense.com/application/poi/display?id=188&type=vulnerabilities
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|