Microsoft MN-500 Wireless Base Station Lets Remote Users Deny Administrative Access
|
|
SecurityTracker Alert ID: 1010550
|
|
SecurityTracker URL: http://securitytracker.com/id?1010550
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jun 21 2004
|
Impact: Denial of service via network
|
Exploit Included: Yes
|
Version(s): MN-500
|
Description: Paul Kurczaba reported a denial of service vulnerability in the Microsoft MN-500 Wireless Base Station. A remote user can deny access to administrators.
It is reported that a remote user can establish 30 connections to the web-based administration port (tcp/80) and keep those connections
open to block any subsequent administrative connections.
The original advisory is available at:
http://www.kurczaba.com/securityadvisories/0406213.htm
|
Impact: A remote user can prevent administrators from accessing the web-based administrative interface.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.microsoft.com/technet/security/ (Links to External Site)
|
Cause: Resource error
|
Reported By: Kurczaba Associates advisories <advisories@kurczaba.com>
|
Message History:
None.
|
Source Message Contents
|
Date: Sun, 20 Jun 2004 22:17:50 -0400
From: Kurczaba Associates advisories <advisories@kurczaba.com>
Subject: Microsoft MN-500 Wireless Router Web-Based Administration DoS
|
Microsoft MN-500 Wireless Router Web-Based Administration DoS
http://www.kurczaba.com/securityadvisories/0406213.htm
-------------------------------------------------------------
Vulnerability ID Number:
0406213
Overview:
A vulnerability has been found in the Microsoft MN-500 Wireless Router Web-Based
Administration.
Vendor:
Microsoft (http://www.microsoft.com)
Vulnerability/Exploit:
A user can deny access to the web-based administration by establishing 30 connections to
the web-based administration port (80). Until the connections are closed, the router
administrator cannot access the web-based administration.
Workaround:
None so far.
Date Discovered:
June 21, 2004
Severity:
Medium
Credit:
Paul Kurczaba
Kurczaba Associates
http://www.kurczaba.com/
Visit http://www.kurczaba.com for mailing lists in Security, Encryption, Wireless,
MS-Security, and Production Security.
|
|