ID

VAR-200805-0397


TITLE

Buffalo router configuration management interface vulnerable to remote access and password leakage

Trust: 0.8

sources: JVNDB: JVNDB-2005-000765

DESCRIPTION

Some Buffalo routers have a vulnerability that could allow remote access from the WAN side. A remote attacker could exploit this vulnerability to manipulate a router by gaining administrative privileges. By accessing the management interface, a remote attacker could also obtain user's account and password information of the ISP using the save settings function.Configurations could be changed by the remote attacker. As the save configuration stores user's account and password information of ISPs in plain-text format, a remote attacker could steal such information and impersonate a user to gain illegal access.

Trust: 0.8

sources: JVNDB: JVNDB-2005-000765

AFFECTED PRODUCTS

vendor:buffalomodel:bbr-4hgscope:lteversion:firmware version 1.04

Trust: 0.8

vendor:buffalomodel:bbr-4mgscope:lteversion:firmware version 1.04

Trust: 0.8

sources: JVNDB: JVNDB-2005-000765

CVSS

SEVERITY

CVSSV2

CVSSV3

IPA: JVNDB-2005-000765
value: MEDIUM

Trust: 0.8

IPA: JVNDB-2005-000765
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

sources: JVNDB: JVNDB-2005-000765

CONFIGURATIONS

sources: JVNDB: JVNDB-2005-000765

PATCH

title:BBR-4HG FarmWareurl:http://buffalo.jp/download/driver/lan/bbr4hg.html

Trust: 0.8

title:BBR-4MG FarmWareurl:http://buffalo.jp/download/driver/lan/bbr4mg.html

Trust: 0.8

sources: JVNDB: JVNDB-2005-000765

EXTERNAL IDS

db:JVNid:JVN55023557

Trust: 0.8

db:JVNDBid:JVNDB-2005-000765

Trust: 0.8

sources: JVNDB: JVNDB-2005-000765

REFERENCES

url:http://jvn.jp/en/jp/jvn55023557/index.html

Trust: 0.8

sources: JVNDB: JVNDB-2005-000765

SOURCES

db:JVNDBid:JVNDB-2005-000765

LAST UPDATE DATE

2022-05-17T02:01:30.868000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2005-000765date:2008-05-21T00:00:00

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2005-000765date:2008-05-21T00:00:00