CVE-2014-6437 Information

Description

Aztech ADSL DSL5018EN (1T1R) DSL705E and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

http://packetstormsecurity.com/files/128254/Aztech-DSL5018EN-DSL705E-DSL705EU-DoS-Broken-Session-Management.html http://www.securityfocus.com/archive/1/533489/100/0/threaded http://www.securityfocus.com/bid/69808

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: