Vulnerability Description
Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the 'Virtual Server' enabled can allow a remote attacker to gain access to mapped services even though the single portmappings may be disabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alliedtelesyn | At-Ar220E | 1.08a |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0125.htmlPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6560
- http://archives.neohapsis.com/archives/bugtraq/2001-05/0125.htmlPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6560
FAQ
What is CVE-2001-0617?
CVE-2001-0617 is a vulnerability with a CVSS score of 7.5 (HIGH). Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the 'Virtual Server' enabled can allow a remote attacker to gain access to mapped services even though the single ...
How severe is CVE-2001-0617?
CVE-2001-0617 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0617?
Check the references section above for vendor advisories and patch information. Affected products include: Alliedtelesyn At-Ar220E.