SureCom Network Device Malformed Web Authorization Request Denial Of Service Vulnerability
BID:9795
Info
SureCom Network Device Malformed Web Authorization Request Denial Of Service Vulnerability
| Bugtraq ID: | 9795 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2004 12:00AM |
| Updated: | Mar 02 2004 12:00AM |
| Credit: | Discovery credited to Vasco Costa. |
| Vulnerable: |
Surecom EP-9510AX Surecom EP-4504AX |
| Not Vulnerable: | |
Discussion
SureCom Network Device Malformed Web Authorization Request Denial Of Service Vulnerability
An issue in the handling of specific web requests by SureCom network devices has been identified. By placing a malformed request to the web configuration interface, it is possible for an attacker to deny service to legitimate users of a vulnerable device.
An issue in the handling of specific web requests by SureCom network devices has been identified. By placing a malformed request to the web configuration interface, it is possible for an attacker to deny service to legitimate users of a vulnerable device.
Exploit / POC
SureCom Network Device Malformed Web Authorization Request Denial Of Service Vulnerability
The following proof-of-concept example has been made available by Vasco Costa:
Authorization: B 00000000
Proof-of-concept exploit code has also been released.
The following proof-of-concept example has been made available by Vasco Costa:
Authorization: B 00000000
Proof-of-concept exploit code has also been released.
Solution / Fix
SureCom Network Device Malformed Web Authorization Request Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SureCom Network Device Malformed Web Authorization Request Denial Of Service Vulnerability
References:
References:
- Vendor Homepage (Surecom)