Vulnerability CVE-2005-2424


Published: 2005-08-03   Modified: 2012-02-12

Description:
The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Siemens -> Santis 50 

 References:
http://www.securenetwork.it/advisories/
http://xforce.iss.net/xforce/xfdb/21552
http://www.securityfocus.com/bid/14372
http://www.osvdb.org/18294
http://secunia.com/advisories/16215
http://marc.theaimsgroup.com/?l=bugtraq&m=112230914431638&w=2

Copyright 2024, cxsecurity.com

 

Back to Top