Linksys BEFVP4 SNMP Community String Information Disclosure Vulnerability
BID:7317
Info
Linksys BEFVP4 SNMP Community String Information Disclosure Vulnerability
| Bugtraq ID: | 7317 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2003 12:00AM |
| Updated: | Apr 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Branson Matheson <[email protected]>. |
| Vulnerable: |
Linksys BEFVP41 1.40 .4 Linksys BEFVP41 1.40 .3f Linksys BEFSR81 |
| Not Vulnerable: | |
Discussion
Linksys BEFVP4 SNMP Community String Information Disclosure Vulnerability
Linksys BEFVP4 VPN router has been reported prone to a sensitive information disclosure vulnerability.
It has been reported that SNMP community strings which, are world readble by default, contain sensitive information pertaining to the internal protected network.
Data collected in this manner may be used in further attacks against the victim network.
It should be noted that this issue has also been reported to affect the Linksys BEFSR81 appliance.
Linksys BEFVP4 VPN router has been reported prone to a sensitive information disclosure vulnerability.
It has been reported that SNMP community strings which, are world readble by default, contain sensitive information pertaining to the internal protected network.
Data collected in this manner may be used in further attacks against the victim network.
It should be noted that this issue has also been reported to affect the Linksys BEFSR81 appliance.
Exploit / POC
Linksys BEFVP4 SNMP Community String Information Disclosure Vulnerability
The following proof of concept was supplied:
snmpwalk -v 1 -c public {ip}
The following proof of concept was supplied:
snmpwalk -v 1 -c public {ip}