Lucene search

K
cveMitreCVE-2001-1484
HistoryJun 21, 2005 - 4:00 a.m.

CVE-2001-1484

2005-06-2104:00:00
mitre
web.nvd.nist.gov
34
cve-2001-1484
alcatel
adsl modems
tftp
remote attackers
firmware
configuration
bounce attack
lan.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.009

Percentile

82.9%

Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.

Affected configurations

Nvd
Node
alcateladsl_modem_1000
OR
alcatelspeed_touch_adsl_modemMatchhome
VendorProductVersionCPE
alcateladsl_modem_1000*cpe:2.3:h:alcatel:adsl_modem_1000:*:*:*:*:*:*:*:*
alcatelspeed_touch_adsl_modemhomecpe:2.3:h:alcatel:speed_touch_adsl_modem:home:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.009

Percentile

82.9%

Related for CVE-2001-1484