3com OfficeConnect allows elevated access

3com-officeconnect-gain-access (16267) The risk level is classified as HighHigh Risk

Description:

3Com OfficeConnect could allow a remote attacker to bypass authentication and gain administrative access to the device. A remote attacker can connect to the router and attempt to authenticate multiple times with an arbitrary username and password. These actions eventually help the attacker to bypass authentication and gain administrative access to the device.


Consequences:

Gain Access

Remedy:

No remedy available as of July 9, 2011.

References:

  • iDEFENSE Security Advisory 05.27.04: 3Com OfficeConnect Remote 812 ADSL Router Authentication Bypass Vulnerability.
  • BID-10426: 3Com OfficeConnect Remote 812 ADSL Router Web Interface Authentication Bypass Vulnerability
  • CVE-2004-0477: Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts using any username and password. NOTE: this identifier was inadvertently re-used for another issue due to a typo; that issue was assigned CVE-2004-0447. This candidate is ONLY for the ADSL router bypass.
  • SA11716: 3Com OfficeConnect 812 ADSL Router Multiple Vulnerabilities

Platforms Affected:

  • 3Com OfficeConnect ADSL Router 812

Reported:

May 27, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page