Lucene search

K
cve[email protected]CVE-2008-1526
HistoryMar 26, 2008 - 10:44 a.m.

CVE-2008-1526

2008-03-2610:44:00
CWE-916
web.nvd.nist.gov
21
zyxel
prestige routers
firmware
vulnerability
password hashing
cve-2008-1526

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

60.1%

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.

Affected configurations

NVD
Node
zyxelp-663hn-51_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-663hn-51_firmwareMatch3.40\(pe9\)
AND
zyxelp-663hn-51Match-
Node
zyxelp-660h-61_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660h-61_firmwareMatch3.40\(pe9\)
AND
zyxelp-660h-61Match-
Node
zyxelp-660h-63_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660h-63_firmwareMatch3.40\(pe9\)
AND
zyxelp-660h-63Match-
Node
zyxelp-660h-67_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660h-67_firmwareMatch3.40\(pe9\)
AND
zyxelp-660h-67Match-
Node
zyxelp-660h-d1_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660h-d1_firmwareMatch3.40\(pe9\)
AND
zyxelp-660h-d1Match-
Node
zyxelp-660h-d3_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660h-d3_firmwareMatch3.40\(pe9\)
AND
zyxelp-660h-d3Match-
Node
zyxelp-660hn-51_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660hn-51_firmwareMatch3.40\(pe9\)
AND
zyxelp-660hn-51Match-
Node
zyxelp-660h-t1_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660h-t1_firmwareMatch3.40\(pe9\)
AND
zyxelp-660h-t1Match-
Node
zyxelp-660hw_d1_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660hw_d1_firmwareMatch3.40\(pe9\)
AND
zyxelp-660hw_d1Match-
Node
zyxelp-660hw_d3_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660hw_d3_firmwareMatch3.40\(pe9\)
AND
zyxelp-660hw_d3Match-
Node
zyxelp-660hw_t3_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-660hw_t3_firmwareMatch3.40\(pe9\)
AND
zyxelp-660hw_t3Match-
Node
zyxelp-661hnu-f1_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-661hnu-f1_firmwareMatch3.40\(pe9\)
AND
zyxelp-661hnu-f1Match-
Node
zyxelp-661h_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-661h_firmwareMatch3.40\(pe9\)
AND
zyxelp-661hMatch-
Node
zyxelp-661hw-d1_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-661hw-d1_firmwareMatch3.40\(pe9\)
AND
zyxelp-661hw-d1Match-
Node
zyxelp-661hnu-f3_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-661hnu-f3_firmwareMatch3.40\(pe9\)
AND
zyxelp-661hnu-f3Match-
Node
zyxelp-662hw-d3_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-662hw-d3_firmwareMatch3.40\(pe9\)
AND
zyxelp-662hw-d3Match-
Node
zyxelp-662hw-d_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-662hw-d_firmwareMatch3.40\(pe9\)
AND
zyxelp-662hw-dMatch-
Node
zyxelp-662hw-d1_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-662hw-d1_firmwareMatch3.40\(pe9\)
AND
zyxelp-662hw-d1Match-
Node
zyxelp-662h-61_firmwareRange3.40\(agd.2\)3.40\(ahq.3\)
OR
zyxelp-662h-61_firmwareMatch3.40\(pe9\)
AND
zyxelp-662h-61Match-

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

60.1%

Related for CVE-2008-1526