20020809 Foundstone Labs Advisory - Information Leakage in Orinoco and Compaq Access Pointsmailing list
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0066.html CVE-2002-0812
Orinoco OEM Residential Gateway - SNMP Community String Remote Configuration
Record summary
CVE-2002-0812 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit.
Description
Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOrinoco OEM Residential Gateway - SNMP Community String Remote ConfigurationExploitDB exploitby Foundstone Inc.Not analyzed1 file
References
520020813 Foundstone Labs Advisory - Information Leakage in Orinoco and Compaq Access Points [updated]mailing list
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0075.html orinoco-rg-default-snmp(9810)vdb entry
http://www.iss.net/security_center/static/9810.php 5436vdb entry
http://www.securityfocus.com/bid/5436 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0812