BT Voyager Multiple Remote Authentication Bypass Vulnerabilities
BID:19057
CVE-2006-3561 |Info
BT Voyager Multiple Remote Authentication Bypass Vulnerabilities
| Bugtraq ID: | 19057 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2006 12:00AM |
| Updated: | Jul 19 2006 10:27PM |
| Credit: | pagvacito <[email protected]> reported these vulnerabilities. |
| Vulnerable: |
BT Voyager 2091 Wireless ADSL Router 0 BT Firmware 3.01m BT Firmware 2.21.05.08m_A2pB018c |
| Not Vulnerable: | |
Discussion
BT Voyager Multiple Remote Authentication Bypass Vulnerabilities
BT Voyager is prone to authentication-bypass vulnerabilities. These issues are due to a flaw in the authentication process of the affected application.
Exploiting these issues may allow attackers to gain unauthorized, remote access to the application's administrative functions.
BT Voyager 2091 Wireless ADSL, Firmware 2.21.05.08m_A2pB018c1.d16d, and Firmware 3.01m are reported vulnerable; other versions may also be affected.
BT Voyager is prone to authentication-bypass vulnerabilities. These issues are due to a flaw in the authentication process of the affected application.
Exploiting these issues may allow attackers to gain unauthorized, remote access to the application's administrative functions.
BT Voyager 2091 Wireless ADSL, Firmware 2.21.05.08m_A2pB018c1.d16d, and Firmware 3.01m are reported vulnerable; other versions may also be affected.
Exploit / POC
BT Voyager Multiple Remote Authentication Bypass Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
BT Voyager Multiple Remote Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
BT Voyager Multiple Remote Authentication Bypass Vulnerabilities
References:
References:
- BT Voyager Web Site (BT Voyager)
- Unauthenticated access to BT Voyager config file and PPP credentials embedded in (pagvacito
)