Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vpn_router_1010 | Nortel | * | * |
Vpn_router_1050 | Nortel | * | * |
Vpn_router_1100 | Nortel | * | * |
Vpn_router_1700 | Nortel | * | * |
Vpn_router_1740 | Nortel | * | * |
Vpn_router_1750 | Nortel | * | * |
Vpn_router_2700 | Nortel | * | * |
Vpn_router_5000 | Nortel | * | * |