CVE-2002-2148
Summary
| CVE | CVE-2002-2148 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information in the response. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lucent | Ascend Max Router | 2.0 | All | All | All |
| Hardware | Lucent | Ascend Max Router | 3.0 | All | All | All |
| Hardware | Lucent | Ascend Max Router | 4.0 | All | All | All |
| Hardware | Lucent | Ascend Max Router | 5.0 | All | All | All |
| Hardware | Lucent | Ascend Max Router | 5.0_ap48 | All | All | All |
| Hardware | Lucent | Ascend Pipeline Router | 1.0 | All | All | All |
| Hardware | Lucent | Ascend Pipeline Router | 2.0 | All | All | All |
| Hardware | Lucent | Ascend Pipeline Router | 3.0 | All | All | All |
| Hardware | Lucent | Ascend Pipeline Router | 4.0 | All | All | All |
| Hardware | Lucent | Ascend Pipeline Router | 5.0 | All | All | All |
| Hardware | Lucent | Ascend Pipeline Router | 6.0 | All | All | All |
| Hardware | Lucent | Ascend Pipeline Router | 6.0.2 | All | All | All |
| Hardware | Lucent | Dslterminator | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | |
| ISS X-Force Database: lucent-port9-information-disclosure (9704): Multiple Lucent router UDP port 9 could disclose sensitive information | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| Multiple Lucent Router UDP Port 9 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.