HIGH · 7.5

CVE-2014-9755

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before ...

Vulnerability Description

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows remote attackers to perform a replay attack.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ViprinetMultichannel Vpn Router 300 Firmware2013070830
ViprinetMultichannel Vpn Router 300-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-9755?

CVE-2014-9755 is a vulnerability with a CVSS score of 7.5 (HIGH). The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before ...

How severe is CVE-2014-9755?

CVE-2014-9755 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9755?

Check the references section above for vendor advisories and patch information. Affected products include: Viprinet Multichannel Vpn Router 300 Firmware, Viprinet Multichannel Vpn Router 300.