Lightwave ConsoleServer brute force password attack
| lightwave-consoleserver-brute-force (6345) |
Description:
Lightwave ConsoleServer 3200 could allow an attacker to obtain a valid username and password using a brute force attack. An attacker can Telnet to the ConsoleServer TCP port 23 for regular access or TCP port 5000 for administrative access and type `loginż at the command line interface. After a failed login attempt, the system immediately returns to the login prompt without termination of the TCP session. An attacker could use this vulnerability to obtain a valid username and password using brute force to gain access to the system..
Platforms Affected:
- Lightwave Communications, Lightwave ConsoleServer 3200
Remedy:
No remedy available as of November 22, 2008.
Consequences:
Gain Access
References:
- BugTraq Mailing List, Tue Apr 10 2001 - 22:08:18 CDT, Console 3200 telnetd problem. at http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html.
- BID-2578: Lightwave ConsoleServer 3200 Information Disclosure Vulnerability
- CVE-2001-0395: Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
- CVE-2001-0396: The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.
Reported:
Apr 11, 2001
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
