{"api_version":"1","generated_at":"2026-07-23T19:55:59+00:00","cve":"CVE-2001-1425","urls":{"html":"https://cve.report/CVE-2001-1425","api":"https://cve.report/api/cve/CVE-2001-1425.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1425","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1425"},"summary":{"title":"CVE-2001-1425","description":"The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-04-10 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/2568","name":"http://www.securityfocus.com/bid/2568","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Alcatel Speed Touch ADSL Insecure Administration Interface Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/175229","name":"http://www.securityfocus.com/archive/1/175229","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/243592","name":"http://www.kb.cert.org/vuls/id/243592","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT/CC Vulnerability Note VU#243592","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html","name":"http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Vulnerabilities in Alcatel ADSL-Ethernet Bridge\ndevices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6354","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6354","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cert.org/advisories/CA-2001-08.html","name":"http://www.cert.org/advisories/CA-2001-08.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT Advisory CA-2001-08 Multiple Vulnerabilities in Alcatel ADSL Modems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1425","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1425","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1425","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"alcatel","cpe5":"speed_touch_home","cpe6":"khdsaa.108","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1425","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"alcatel","cpe5":"speed_touch_home","cpe6":"khdsaa.132","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1425","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"alcatel","cpe5":"speed_touch_home","cpe6":"khdsaa.133","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1425","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"alcatel","cpe5":"speed_touch_home","cpe6":"khdsaa.134","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:58:11.422Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#243592","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/243592"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html"},{"name":"alcatel-expert-account(6354)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6354"},{"name":"20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/175229"},{"name":"2568","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/2568"},{"name":"CA-2001-08","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.cert.org/advisories/CA-2001-08.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-04-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"VU#243592","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/243592"},{"tags":["x_refsource_MISC"],"url":"http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html"},{"name":"alcatel-expert-account(6354)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6354"},{"name":"20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/175229"},{"name":"2568","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/2568"},{"name":"CA-2001-08","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.cert.org/advisories/CA-2001-08.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1425","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#243592","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/243592"},{"name":"http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html","refsource":"MISC","url":"http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html"},{"name":"alcatel-expert-account(6354)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6354"},{"name":"20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/175229"},{"name":"2568","refsource":"BID","url":"http://www.securityfocus.com/bid/2568"},{"name":"CA-2001-08","refsource":"CERT","url":"http://www.cert.org/advisories/CA-2001-08.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1425","datePublished":"2005-03-22T05:00:00.000Z","dateReserved":"2005-03-22T00:00:00.000Z","dateUpdated":"2024-08-08T04:58:11.422Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-04-10 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:alcatel:speed_touch_home:khdsaa.108:*:*:*:*:*:*:*","matchCriteriaId":"91040F84-5FFF-455F-B81A-EE2F450E878B"},{"vulnerable":true,"criteria":"cpe:2.3:h:alcatel:speed_touch_home:khdsaa.132:*:*:*:*:*:*:*","matchCriteriaId":"5983F496-F470-4347-95DA-CF59EB3956E3"},{"vulnerable":true,"criteria":"cpe:2.3:h:alcatel:speed_touch_home:khdsaa.133:*:*:*:*:*:*:*","matchCriteriaId":"13D1F571-1947-4FDB-AE33-D1FD86E9116B"},{"vulnerable":true,"criteria":"cpe:2.3:h:alcatel:speed_touch_home:khdsaa.134:*:*:*:*:*:*:*","matchCriteriaId":"10C8A4DE-F452-4063-A82E-0033190C490A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1425","Ordinal":"1","Title":"CVE-2001-1425","CVE":"CVE-2001-1425","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1425","Ordinal":"1","NoteData":"The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.","Type":"Description","Title":"CVE-2001-1425"},{"CveYear":"2001","CveId":"1425","Ordinal":"2","NoteData":"2005-03-22","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"1425","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}