CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3173  CVE-2001-0352  Candidate  SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.  Proposed (20010727)  ACCEPT(3) Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall  Frech> XF:3com-ap-wep-key(6232) | Christey> BID:2899 | URL:http://www.securityfocus.com/bid/2899  View
3430  CVE-2001-0617  Candidate  Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the "Virtual Server" enabled can allow a remote attacker to gain access to mapped services even though the single portmappings may be disabled.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop    View
3431  CVE-2001-0618  Candidate  Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the "Network Name" or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occurs in the clear during communications, a remote attacker could determine the WEP key and decrypt RG-1000 traffic.  Proposed (20010727)  ACCEPT(1) Frech | MODIFY(1) Ziese | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Bishop  Ziese> vulnerability, per se, then why is this? If WEP is delievred enabled, by | any vendor, it must give the existing/default WEP-key somewhere. Will every | hardware product be flawed by his definition?  View
3432  CVE-2001-0619  Candidate  The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The "Network Name" or SSID, which is used as a shared secret to join the network, is transmitted in the clear.  Proposed (20010727)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REJECT(1) Ziese | REVIEWING(1) Bishop  Frech> XF:orinoco-ap-plaintext-ssid(7005)  View
3433  CVE-2001-0620  Candidate  iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop    View

Page 283 of 20943, showing 5 records out of 104715 total, starting on record 1411, ending on 1415

Actions