Show plain JSON{"id": "CVE-2008-1524", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2008-03-26T10:44:00.000", "references": [{"url": "http://www.gnucitizen.org/projects/router-hacking-challenge/", "source": "cve@mitre.org"}, {"url": "http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/489009/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.gnucitizen.org/projects/router-hacking-challenge/", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/489009/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-16"}]}], "descriptions": [{"lang": "en", "value": "The SNMP service on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has \"public\" as its default community for both (1) read and (2) write operations, which allows remote attackers to perform administrative actions via SNMP, as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable, which is displayed on the System Status page."}, {"lang": "es", "value": "El servicio SNMP de los routers ZyXEL Prestige, incluyendo los modelos P-660 y P-661 con firmware 3.40(AGD.2) hasta la 3.40(AHQ.3), tienen \u201cpublic\u201d como comunidad por defecto (default community) tanto para operaciones de (1) lectura como de (2) escritura, lo cual permite a atacantes remotos realizar tareas administrativas a trav\u00e9s de SNMP, tal y como se ha demostrado leyendo la contrase\u00f1a del Servicio Dynamic DNS o insertando una secuencia XSS en la variable system.sysName.0, que se visualiza en la p\u00e1gina System Status."}], "lastModified": "2024-11-21T00:44:43.913", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:zyxel:prestige_660:h-d1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9B37DD5-40E7-43E3-8183-A755C488E383"}, {"criteria": "cpe:2.3:h:zyxel:prestige_660:h-d3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2850459-830C-49FD-89F8-0693E6D33543"}, {"criteria": "cpe:2.3:h:zyxel:prestige_661:hw-d1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C2C98B6-E370-4E2C-988D-CC3F3AA78126"}, {"criteria": "cpe:2.3:h:zyxel:zynos:3.40:agd.2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC9ED360-9257-477C-8F21-0CD4C1D38F42"}, {"criteria": "cpe:2.3:h:zyxel:zynos:3.40:agl.3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B170D9D8-4A01-4A97-947C-F978B07045C2"}, {"criteria": "cpe:2.3:h:zyxel:zynos:3.40:ahq.0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D759579-E9E7-4344-BA88-CACECFB9C731"}, {"criteria": "cpe:2.3:h:zyxel:zynos:3.40:ahq.3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35DB7E44-E00E-41E3-A701-FB5DAC8E48E1"}, {"criteria": "cpe:2.3:h:zyxel:zynos:3.40:ahz.0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2344FB7D-785D-4C52-BF27-1EEAAB2726B8"}, {"criteria": "cpe:2.3:h:zyxel:zynos:3.40:atm.0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CEA7FE7B-31E2-4164-882B-2E9712F95044"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}