3Com OfficeConnect ADSL Router Port Address Translation Access Control Bypassing Vulnerability
BID:4841
Info
3Com OfficeConnect ADSL Router Port Address Translation Access Control Bypassing Vulnerability
| Bugtraq ID: | 4841 |
| Class: | Design Error |
| CVE: |
CVE-2002-0888 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Vulnerability discovery credited to Ismael Briones <[email protected]>. |
| Vulnerable: |
3Com OfficeConnect DSL Router 812 1.1.9 3Com OfficeConnect DSL Router 812 1.1.7 |
| Not Vulnerable: | |
Discussion
3Com OfficeConnect ADSL Router Port Address Translation Access Control Bypassing Vulnerability
OfficeConnect ADSL routers are a hardware and switch solution distributed by 3Com.
Under some circumstances, it may be possible for a remote user to gain unauthorized access to information systems behind a 3Com OfficeConnect router. The OfficeConnect does not properly handle PAT, and may allow a remote attacker to connect to arbitrary ports on a system behind a PAT rule.
It has been reported that this issue results when iPAT/iNAT is enabled.
OfficeConnect ADSL routers are a hardware and switch solution distributed by 3Com.
Under some circumstances, it may be possible for a remote user to gain unauthorized access to information systems behind a 3Com OfficeConnect router. The OfficeConnect does not properly handle PAT, and may allow a remote attacker to connect to arbitrary ports on a system behind a PAT rule.
It has been reported that this issue results when iPAT/iNAT is enabled.