HIGH · 7.5

CVE-2001-1484

Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) si...

Vulnerability Description

Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AlcatelAdsl Modem 1000All versions
AlcatelSpeed Touch Adsl Modemhome

References

FAQ

What is CVE-2001-1484?

CVE-2001-1484 is a vulnerability with a CVSS score of 7.5 (HIGH). Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) si...

How severe is CVE-2001-1484?

CVE-2001-1484 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-1484?

Check the references section above for vendor advisories and patch information. Affected products include: Alcatel Adsl Modem 1000, Alcatel Speed Touch Adsl Modem.