CVE-2013-4877

The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:verizon:wireless_network_extender:scs-2u01:*:*:*:*:*:*:*
cpe:2.3:h:verizon:wireless_network_extender:scs-26uc4:*:*:*:*:*:*:*

History

21 Nov 2024, 01:56

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/458007 - US Government Resource () http://www.kb.cert.org/vuls/id/458007 - US Government Resource
References () http://www.kb.cert.org/vuls/id/BLUU-997M5B - US Government Resource () http://www.kb.cert.org/vuls/id/BLUU-997M5B - US Government Resource
References () http://www.securityfocus.com/bid/61169 - () http://www.securityfocus.com/bid/61169 -

Information

Published : 2013-07-18 16:51

Updated : 2024-11-21 01:56


NVD link : CVE-2013-4877

Mitre link : CVE-2013-4877

CVE.ORG link : CVE-2013-4877


JSON object : View

Products Affected

verizon

  • wireless_network_extender
CWE
CWE-287

Improper Authentication