3Com Wireless 8760 Dual-Radio 11a/b/g PoE Multiple Security Vulnerabilities
BID:32358
Info
3Com Wireless 8760 Dual-Radio 11a/b/g PoE Multiple Security Vulnerabilities
| Bugtraq ID: | 32358 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2008 12:00AM |
| Updated: | Nov 19 2008 06:04PM |
| Credit: | Adrian Pastor of ProCheckUp Ltd |
| Vulnerable: |
3Com 3Com Wireless 8760 Dual-Radio 11a/b/g PoE 0 |
| Not Vulnerable: | |
Discussion
3Com Wireless 8760 Dual-Radio 11a/b/g PoE Multiple Security Vulnerabilities
3Com Wireless 8760 Dual-Radio 11a/b/g PoE Access Point is prone to multiple security vulnerabilities, including an HTML-injection issue and an authentication-bypass issue.
Successfully exploiting these issues will allow an attacker to obtain administrative credentials, bypass security mechanisms, or run attacker-supplied HTML and script code in the context of the web administration interface. The attacker may then be able to steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.
3Com Wireless 8760 Dual-Radio 11a/b/g PoE Access Point is prone to multiple security vulnerabilities, including an HTML-injection issue and an authentication-bypass issue.
Successfully exploiting these issues will allow an attacker to obtain administrative credentials, bypass security mechanisms, or run attacker-supplied HTML and script code in the context of the web administration interface. The attacker may then be able to steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.
Exploit / POC
3Com Wireless 8760 Dual-Radio 11a/b/g PoE Multiple Security Vulnerabilities
Attackers can exploit these issues using readily available tools, including a web browser.
The following example 'snmpset' command to change the device's system name is available:
snmpset -v2c -c private 192.168.1.1 sysName.0 s "PAYLOAD_GOES_HERE"
Attackers can exploit these issues using readily available tools, including a web browser.
The following example 'snmpset' command to change the device's system name is available:
snmpset -v2c -c private 192.168.1.1 sysName.0 s "PAYLOAD_GOES_HERE"
Solution / Fix
3Com Wireless 8760 Dual-Radio 11a/b/g PoE Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
3Com Wireless 8760 Dual-Radio 11a/b/g PoE Multiple Security Vulnerabilities
References:
References:
- PR07-40: Authentication Bypass, Passwords Leakage and SNMP Injection on 3Com AP (ProCheckUp Research
) - Product Homepage (3Com)