HIGH · 9.0

CVE-2007-2332

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force a...

Vulnerability Description

Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
NortelVpn Router 1010All versions
NortelVpn Router 1050All versions
NortelVpn Router 1100All versions
NortelVpn Router 1700All versions
NortelVpn Router 1740All versions
NortelVpn Router 1750All versions
NortelVpn Router 2700All versions
NortelVpn Router 5000All versions

References

FAQ

What is CVE-2007-2332?

CVE-2007-2332 is a vulnerability with a CVSS score of 9.0 (HIGH). Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force a...

How severe is CVE-2007-2332?

CVE-2007-2332 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2332?

Check the references section above for vendor advisories and patch information. Affected products include: Nortel Vpn Router 1010, Nortel Vpn Router 1050, Nortel Vpn Router 1100, Nortel Vpn Router 1700, Nortel Vpn Router 1740.