Lucene search

K
cve[email protected]CVE-2013-4708
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-4708

2022-10-0316:14:57
CWE-310
web.nvd.nist.gov
23
cve
2013
4708
pppac
internet initiative japan inc.
seil
predictable random numbers
radius authentication
bypass

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.6%

The PPP Access Concentrator (PPPAC) in Internet Initiative Japan Inc. SEIL/x86 1.00 through 2.80, SEIL/X1 1.00 through 4.30, SEIL/X2 1.00 through 4.30, SEIL/B1 1.00 through 4.30, SEIL/Turbo 1.80 through 2.15, and SEIL/neu 2FE Plus 1.80 through 2.15 generates predictable random numbers, which allows remote attackers to bypass RADIUS authentication by sniffing RADIUS traffic.

Affected configurations

NVD
Node
iijseil\%2fx1_firmwareMatch1.00
OR
iijseil\%2fx1_firmwareMatch4.30
AND
iijseil\/x1
Node
iijseil\%2fb1_firmwareMatch1.00
OR
iijseil\%2fb1_firmwareMatch4.30
AND
iijseil\/b1
Node
iijseil\%2fx2_firmwareMatch1.00
OR
iijseil\%2fx2_firmwareMatch4.30
AND
iijseil\/x2
Node
iijseil\%2fx86_firmwareMatch1.00
OR
iijseil\%2fx86_firmwareMatch2.80
AND
iijseil\/x86
Node
iijseil\%2fturbo_firmwareMatch1.80
OR
iijseil\%2fturbo_firmwareMatch2.05
OR
iijseil\%2fturbo_firmwareMatch2.15
AND
iijseil\/turbo
Node
iijseil\%2fneu_2fe_plus_firmwareMatch1.80
OR
iijseil\%2fneu_2fe_plus_firmwareMatch2.05
OR
iijseil\%2fneu_2fe_plus_firmwareMatch2.15
AND
iijseil\/neu_2fe_plus

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

56.6%

Related for CVE-2013-4708