CVE Vulnerabilities

CVE-2007-2332

Published: Apr 27, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.

Affected Software

NameVendorStart VersionEnd Version
Vpn_router_1010Nortel**
Vpn_router_1050Nortel**
Vpn_router_1100Nortel**
Vpn_router_1700Nortel**
Vpn_router_1740Nortel**
Vpn_router_1750Nortel**
Vpn_router_2700Nortel**
Vpn_router_5000Nortel**

References