Siemens Santis 50 Wireless Router Web Interface Denial Of Service Vulnerability
BID:14372
Info
Siemens Santis 50 Wireless Router Web Interface Denial Of Service Vulnerability
| Bugtraq ID: | 14372 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2005 12:00AM |
| Updated: | Jul 25 2005 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Secure Network <[email protected]>. |
| Vulnerable: |
Siemens Santis 50 Wireless router 4.2.8 .0 firmware |
| Not Vulnerable: | |
Discussion
Siemens Santis 50 Wireless Router Web Interface Denial Of Service Vulnerability
Siemens Santis 50 Wireless router Web interface is affected by a remote denial of service vulnerability.
An attacker can exploit this issue to deny service to the Web interface and gain access to privileged functions of the telnet CLI. These functions enable the attacker to discover information about the configuration of the device and connections. The attacker can also erase the FLASH contents.
Information obtained may be used in further attacks against the vulnerable device or the network it operates on.
This issue may also affect the Ericsson HN294dp and Dynalink RTA300W routers. Both devices are believed to use the same hardware as the Siemens Santis 50 Wireless router; this has not been confirmed by Symantec.
Siemens Santis 50 Wireless router Web interface is affected by a remote denial of service vulnerability.
An attacker can exploit this issue to deny service to the Web interface and gain access to privileged functions of the telnet CLI. These functions enable the attacker to discover information about the configuration of the device and connections. The attacker can also erase the FLASH contents.
Information obtained may be used in further attacks against the vulnerable device or the network it operates on.
This issue may also affect the Ericsson HN294dp and Dynalink RTA300W routers. Both devices are believed to use the same hardware as the Siemens Santis 50 Wireless router; this has not been confirmed by Symantec.
Exploit / POC
Siemens Santis 50 Wireless Router Web Interface Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Siemens Santis 50 Wireless Router Web Interface Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Siemens Santis 50 Wireless Router Web Interface Denial Of Service Vulnerability
References:
References:
- Welcome to Siemens ADSL Products (Siemens)
- Siemens SANTIS 50 Authentication Vulnerability (Secure Network)