Linksys BEFVP41 Key Truncation Encryption Weakening Vulnerability
BID:4250
Info
Linksys BEFVP41 Key Truncation Encryption Weakening Vulnerability
| Bugtraq ID: | 4250 |
| Class: | Design Error |
| CVE: |
CVE-2002-0426 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Vulnerability discovery credited to Phil Schlesinger <[email protected]>. |
| Vulnerable: |
Linksys EtherFast BEFVP41 Router |
| Not Vulnerable: | |
Discussion
Linksys BEFVP41 Key Truncation Encryption Weakening Vulnerability
The BEFVP41 is a hardware router implementation. It is distributed and maintained by Linksys.
Triple DES keying on the BEFVP41 supports a maximum of 48 hex character keys for encryption by specification. However, when a user attempts to manually enter a generated Triple DES key of any length greater than 23 bytes, the key is truncated to a maximum of 23 bytes.
This problem also exists in the MD5 authentication key, which by specification can be a maximum of 32 hex characters. Manual entry of the key results in a truncated key maximum length of 19 bytes.
This problem results in weakened encryption keys, and could increase the probability of successful brute force encryption attack and data recovery.
The BEFVP41 is a hardware router implementation. It is distributed and maintained by Linksys.
Triple DES keying on the BEFVP41 supports a maximum of 48 hex character keys for encryption by specification. However, when a user attempts to manually enter a generated Triple DES key of any length greater than 23 bytes, the key is truncated to a maximum of 23 bytes.
This problem also exists in the MD5 authentication key, which by specification can be a maximum of 32 hex characters. Manual entry of the key results in a truncated key maximum length of 19 bytes.
This problem results in weakened encryption keys, and could increase the probability of successful brute force encryption attack and data recovery.
Exploit / POC
Linksys BEFVP41 Key Truncation Encryption Weakening Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.