Atmel SNMP Community String Vulnerability
BID:2896
Info
Atmel SNMP Community String Vulnerability
| Bugtraq ID: | 2896 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2001 12:00AM |
| Updated: | Jun 20 2001 12:00AM |
| Credit: | This vulnerability was announced in an IIS X-Force Security Advisory on June 20, 2001. |
| Vulnerable: |
Atmel Firmware 1.3 |
| Not Vulnerable: |
Atmel Firmware 1.4 |
Discussion
Atmel SNMP Community String Vulnerability
Atmel is a chip design and manufacturing firm that provides various RF-based products to corporate consumers. Atmel manufactures firmware for various wireless access systems.
It is possible to gain SNMP access to some wireless access points that use the Atmel chipset and firmware. These systems do not use sufficient access control, and allow reading/writing of MIB data with any community password.
This makes it possible for a remote user to gain access to sensitive information, and potentially launch an information gathering attack.
Atmel is a chip design and manufacturing firm that provides various RF-based products to corporate consumers. Atmel manufactures firmware for various wireless access systems.
It is possible to gain SNMP access to some wireless access points that use the Atmel chipset and firmware. These systems do not use sufficient access control, and allow reading/writing of MIB data with any community password.
This makes it possible for a remote user to gain access to sensitive information, and potentially launch an information gathering attack.
Exploit / POC
Atmel SNMP Community String Vulnerability
See discussion.
See discussion.
Solution / Fix
Atmel SNMP Community String Vulnerability
Solution:
Updates available:
Atmel Firmware 1.3
Solution:
Updates available:
Atmel Firmware 1.3
-
Linksys WAP11 1.4
http://www.linksys.com/download/firmware.asp -
Netgear ME102
http://www.netgear.com/customer_services.asp