Linksys DSL Router SNMP Trap System Arbitrary Sending Vulnerability
BID:3795
Info
Linksys DSL Router SNMP Trap System Arbitrary Sending Vulnerability
| Bugtraq ID: | 3795 |
| Class: | Design Error |
| CVE: |
CVE-2002-0109 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was announced by Matthew S. Hallacy <[email protected]> via Bugtraq on January 6, 2002. |
| Vulnerable: |
Linksys EtherFast BEFSR81 Router Linksys EtherFast BEFN2PS4 Router |
| Not Vulnerable: | |
Discussion
Linksys DSL Router SNMP Trap System Arbitrary Sending Vulnerability
Linksys DSL routers are high-speed internet access solutions distributed by the Linksys Group. Linksys DSL routers offer features such as high-speed internet access, switching built into some routers, and Voice-over-IP.
A problem with Linksys routers could make it possible for a remote user to gain sensitive information from a Linksys router, or potentially create a denial of service. The problem affects Linksys routers which may work with either Microsoft or Unix and Linux systems.
Linksys routers have a design issue that will router SNMP Trap information to any address. When a Linksys router receives a query from a system, the router alters it's own configuration to make the querying system the SNMP Trap system. This can yield sensitive information about network traffic being handled by the router. Since SNMP uses UDP as it's method of transport, this could also lead to a number of vulnerable routers being used to create a distributed denial of service attack.
Linksys DSL routers are high-speed internet access solutions distributed by the Linksys Group. Linksys DSL routers offer features such as high-speed internet access, switching built into some routers, and Voice-over-IP.
A problem with Linksys routers could make it possible for a remote user to gain sensitive information from a Linksys router, or potentially create a denial of service. The problem affects Linksys routers which may work with either Microsoft or Unix and Linux systems.
Linksys routers have a design issue that will router SNMP Trap information to any address. When a Linksys router receives a query from a system, the router alters it's own configuration to make the querying system the SNMP Trap system. This can yield sensitive information about network traffic being handled by the router. Since SNMP uses UDP as it's method of transport, this could also lead to a number of vulnerable routers being used to create a distributed denial of service attack.
Exploit / POC
Linksys DSL Router SNMP Trap System Arbitrary Sending Vulnerability
This vulnerability may be exploited with one of the many available SNMP query tools.
This vulnerability may be exploited with one of the many available SNMP query tools.
Solution / Fix
Linksys DSL Router SNMP Trap System Arbitrary Sending Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Linksys DSL Router SNMP Trap System Arbitrary Sending Vulnerability
References:
References: