CVE-2001-1425
Summary
| CVE | CVE-2001-1425 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-04-10 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Alcatel | Speed Touch Home | khdsaa.108 | All | All | All |
| Hardware | Alcatel | Speed Touch Home | khdsaa.132 | All | All | All |
| Hardware | Alcatel | Speed Touch Home | khdsaa.133 | All | All | All |
| Hardware | Alcatel | Speed Touch Home | khdsaa.134 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Alcatel Speed Touch ADSL Insecure Administration Interface Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CERT/CC Vulnerability Note VU#243592 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Multiple Vulnerabilities in Alcatel ADSL-Ethernet Bridge devices | af854a3a-2127-422b-91ae-364da2661108 | security.sdsc.edu | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CERT Advisory CA-2001-08 Multiple Vulnerabilities in Alcatel ADSL Modems | af854a3a-2127-422b-91ae-364da2661108 | www.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.