HTTP: 3COM 3CRADSL72 Wireless Router Information Disclosure

This signature detects attempts to access a 3COM wireless router web page that contains sensitive administrative information. No authentication is required to access this page.

Extended Description

It is reported that this issue arises due to an access validation error and may allow remote unauthorized attackers to gain access to sensitive hidden Web pages through the product's Web management interface. 3Com OfficeConnect Wireless 11g Access Point 3CRWE454G72 firmware versions prior to 1.03.07A are reported prone to this vulnerability.

Affected Products

3com officeconnect_wireless11g_access_point_3crwe454g72

Short Name
HTTP:3COM:3COM-PASS-LEAK
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
3COM 3CRADSL72 CVE-2005-0112 Disclosure Information Router Wireless bid:12322
Release Date
10/21/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

3com

CVSS Score

5.0

Found a potential security threat?