CVE Vulnerabilities

CVE-2009-4409

Improper Authentication

Published: Dec 23, 2009 | Modified: Jan 06, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet Initiative Japan SEIL/B1 firmware 1.00 through 2.52 use the same challenge for each authentication attempt, which allows remote attackers to bypass authentication via a replay attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Seil/b1 Iij 1.00 (including) 1.00 (including)
Seil/b1 Iij 2.01 (including) 2.01 (including)
Seil/b1 Iij 2.10 (including) 2.10 (including)
Seil/b1 Iij 2.20 (including) 2.20 (including)
Seil/b1 Iij 2.30 (including) 2.30 (including)
Seil/b1 Iij 2.40 (including) 2.40 (including)
Seil/b1 Iij 2.41 (including) 2.41 (including)
Seil/b1 Iij 2.42 (including) 2.42 (including)
Seil/b1 Iij 2.50 (including) 2.50 (including)
Seil/b1 Iij 2.51 (including) 2.51 (including)
Seil/b1 Iij 2.52 (including) 2.52 (including)

Potential Mitigations

References