ID

VAR-201406-0502


TITLE

Multiple Sitecom Products Admin Password Key Security Restriction Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2014-03891

DESCRIPTION

SITECOM WLR-4000/ WLR-4004 is a router. Multiple Sitecom products have an Admin cryptographic key security restriction bypass vulnerability, as the device generates a predictive way of managing passwords and WPA2 passphrases. Allows remote attackers to more easily obtain this information, allowing them to potentially access the device. This may lead to other attacks. The following products are vulnerable: Sitecom WLR-4000 v1 001 Sitecom WLR-4004 v1 001

Trust: 0.81

sources: CNVD: CNVD-2014-03891 // BID: 67717

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03891

AFFECTED PRODUCTS

vendor:sitecommodel:wlr-4004scope:eqversion:1.23

Trust: 0.6

vendor:sitecommodel:wlr-4000scope:eqversion:1.23

Trust: 0.6

vendor:sitecommodel:wlr-4004scope:eqversion:v10010

Trust: 0.3

vendor:sitecommodel:wlr-4000scope:eqversion:v10010

Trust: 0.3

sources: CNVD: CNVD-2014-03891 // BID: 67717

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-03891
value: LOW

Trust: 0.6

CNVD: CNVD-2014-03891
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-03891

THREAT TYPE

local

Trust: 0.3

sources: BID: 67717

TYPE

Design Error

Trust: 0.3

sources: BID: 67717

EXTERNAL IDS

db:BIDid:67717

Trust: 0.9

db:OSVDBid:107558

Trust: 0.6

db:CNVDid:CNVD-2014-03891

Trust: 0.6

sources: CNVD: CNVD-2014-03891 // BID: 67717

REFERENCES

url:http://www.osvdb.com/107558

Trust: 0.6

url:http://www.sitecom.com

Trust: 0.3

url:http://blog.emaze.net/2014/04/sitecom-firmware-and-wifi.html

Trust: 0.3

sources: CNVD: CNVD-2014-03891 // BID: 67717

CREDITS

Roberto Paleari and Alessandro Di Pinto

Trust: 0.3

sources: BID: 67717

SOURCES

db:CNVDid:CNVD-2014-03891
db:BIDid:67717

LAST UPDATE DATE

2022-05-17T01:47:58.899000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03891date:2014-06-26T00:00:00
db:BIDid:67717date:2014-04-24T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03891date:2014-06-26T00:00:00
db:BIDid:67717date:2014-04-24T00:00:00