CVE Vulnerabilities

CVE-2009-4409

Improper Authentication

Published: Dec 23, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allows remote attackers to bypass authentication via a replay attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Seil/b1Iij1.00 (including)1.00 (including)
Seil/b1Iij2.01 (including)2.01 (including)
Seil/b1Iij2.10 (including)2.10 (including)
Seil/b1Iij2.20 (including)2.20 (including)
Seil/b1Iij2.30 (including)2.30 (including)
Seil/b1Iij2.40 (including)2.40 (including)
Seil/b1Iij2.41 (including)2.41 (including)
Seil/b1Iij2.42 (including)2.42 (including)
Seil/b1Iij2.50 (including)2.50 (including)
Seil/b1Iij2.51 (including)2.51 (including)
Seil/b1Iij2.52 (including)2.52 (including)

Potential Mitigations

References