Vulnerability Description
DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linksys | Befcmu10 | All versions |
| Linksys | Befn2Ps4 | All versions |
| Linksys | Befsr11 | 1.40.2 |
| Linksys | Befsr41 | 1.35 |
| Linksys | Befsr41W | All versions |
| Linksys | Befsr81 | All versions |
| Linksys | Befsru31 | 1.40.2 |
| Linksys | Befsx41 | 1.42.7 |
| Linksys | Befvp41 | All versions |
| Linksys | Rv082 | All versions |
| Linksys | Wap55Ag | 1.0.7 |
| Linksys | Wrt54G | 1.42.3 |
References
- http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=
- http://marc.info/?l=bugtraq&m=108662876129301&w=2
- http://secunia.com/advisories/11606
- http://securitytracker.com/alerts/2004/May/1010288.html
- http://www.osvdb.org/6325
- http://www.securityfocus.com/bid/10329ExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16142
- http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=
- http://marc.info/?l=bugtraq&m=108662876129301&w=2
- http://secunia.com/advisories/11606
- http://securitytracker.com/alerts/2004/May/1010288.html
- http://www.osvdb.org/6325
- http://www.securityfocus.com/bid/10329ExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16142
FAQ
What is CVE-2004-0580?
CVE-2004-0580 is a vulnerability with a CVSS score of 5.0 (MEDIUM). DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote...
How severe is CVE-2004-0580?
CVE-2004-0580 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0580?
Check the references section above for vendor advisories and patch information. Affected products include: Linksys Befcmu10, Linksys Befn2Ps4, Linksys Befsr11, Linksys Befsr41, Linksys Befsr41W.