ID

VAR-201308-0493


TITLE

Broadkam PJ871 Verification Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2013-11027

DESCRIPTION

The Broadkam PJ871 is a DSL router device. The Broadkam PJ871 DSL Router does not properly validate password replacement requests, allowing remote attackers to exploit vulnerabilities to submit special requests, change any user password, and grant unauthorized access to the appliance. Broadkam PJ871 is prone to an authentication-bypass vulnerability. An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. http://drupal.org/node/207891

Trust: 0.81

sources: CNVD: CNVD-2013-11027 // BID: 61461

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-11027

AFFECTED PRODUCTS

vendor:broadkammodel:pj871scope: - version: -

Trust: 0.6

vendor:broadkammodel:pj871scope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2013-11027 // BID: 61461

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-11027
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2013-11027
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-11027

THREAT TYPE

network

Trust: 0.3

sources: BID: 61461

TYPE

Access Validation Error

Trust: 0.3

sources: BID: 61461

EXTERNAL IDS

db:BIDid:61461

Trust: 0.9

db:PACKETSTORMid:122543

Trust: 0.6

db:CNVDid:CNVD-2013-11027

Trust: 0.6

sources: CNVD: CNVD-2013-11027 // BID: 61461

REFERENCES

url:http://packetstormsecurity.com/files/122543/broadkam-pj871-authentication-bypass.html

Trust: 0.6

url:http://www.marketonline.ir/adsl/index.php?route=product/product&product_id=52

Trust: 0.3

sources: CNVD: CNVD-2013-11027 // BID: 61461

CREDITS

d3c0der

Trust: 0.3

sources: BID: 61461

SOURCES

db:CNVDid:CNVD-2013-11027
db:BIDid:61461

LAST UPDATE DATE

2022-05-17T02:08:09.734000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-11027date:2013-08-01T00:00:00
db:BIDid:61461date:2013-07-25T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-11027date:2013-08-01T00:00:00
db:BIDid:61461date:2013-07-25T00:00:00