Short Name |
HTTP:3COM:3COM-PASS-LEAK |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
3COM 3CRADSL72 Wireless Router Information Disclosure |
Release Date |
2004/10/20 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to access a 3COM wireless router web page that contains sensitive administrative information. No authentication is required to access this page.
It is reported that this issue arises due to an access validation error and may allow remote unauthorized attackers to gain access to sensitive hidden Web pages through the product's Web management interface. 3Com OfficeConnect Wireless 11g Access Point 3CRWE454G72 firmware versions prior to 1.03.07A are reported prone to this vulnerability.