CVE Vulnerabilities

CVE-2007-2332

Published: Apr 27, 2007 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.

Affected Software

Name Vendor Start Version End Version
Vpn_router_1010 Nortel * *
Vpn_router_1050 Nortel * *
Vpn_router_1100 Nortel * *
Vpn_router_1700 Nortel * *
Vpn_router_1740 Nortel * *
Vpn_router_1750 Nortel * *
Vpn_router_2700 Nortel * *
Vpn_router_5000 Nortel * *

References