SMC7004VWBR and SMC7008ABR Authentication Bypass Vulnerability
BID:11197
Info
SMC7004VWBR and SMC7008ABR Authentication Bypass Vulnerability
| Bugtraq ID: | 11197 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2004 12:00AM |
| Updated: | Sep 15 2004 12:00AM |
| Credit: | Jimmy Scott <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
SMC SMC7008ABR 1.32 SMC SMC7004VWBR 1.23 SMC SMC7004VWBR 1.22 SMC SMC7004VWBR 1.21 a |
| Not Vulnerable: | |
Discussion
SMC7004VWBR and SMC7008ABR Authentication Bypass Vulnerability
SMC 7004VWBR, and 7008ABR devices are reportedly susceptible to an authentication bypass vulnerability in their web administration interface.
This vulnerability exists due to the method by which the web administration software validates authenticated users. Reportedly, the software uses the source IP address of the web client to differentiate between users accessing the administration interface.
This vulnerability allows attackers to gain administrative access to affected devices.
SMC 7004VWBR, and 7008ABR devices are reportedly susceptible to an authentication bypass vulnerability in their web administration interface.
This vulnerability exists due to the method by which the web administration software validates authenticated users. Reportedly, the software uses the source IP address of the web client to differentiate between users accessing the administration interface.
This vulnerability allows attackers to gain administrative access to affected devices.
Exploit / POC
SMC7004VWBR and SMC7008ABR Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
SMC7004VWBR and SMC7008ABR Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SMC7004VWBR and SMC7008ABR Authentication Bypass Vulnerability
References:
References:
- SMC Homepage (SMC)
- SMC7004VWBR / SMC7008ABR "spoofing" vulnerability. (Jimmy Scott
)