CVE-2000-0470: High severity Allegro Rom Pager vulnerability
Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
AllegroSoft RomPagerfrom your environment.Uninstall or disable AllegroSoft RomPager if it is not required. Remove the RomPager HTTP server binary/firmware component or disable the HTTP management service to eliminate exposure.
- Compensating control
Restrict access to the RomPager HTTP interface to trusted IPs using firewall rules or network ACLs. Block external or untrusted access to the device's HTTP management port to prevent remote exploitation.
- Compensating control
Deploy network-level protections (WAF/IPS) or request-filtering to detect and block malformed HTTP authentication requests targeting RomPager.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0470?
CVE-2000-0470 is classified as a denial of service vulnerability.
How does CVE-2000-0470 affect users of Allegro RomPager?
CVE-2000-0470 allows remote attackers to disrupt service by sending a malformed authentication request to the server.
What versions of Allegro RomPager are affected by CVE-2000-0470?
Allegro RomPager version 2.10 is specifically vulnerable to CVE-2000-0470.
How can I mitigate the risks associated with CVE-2000-0470?
To mitigate CVE-2000-0470, avoid using the vulnerable version of Allegro RomPager and implement network security measures.
Is there a patch available for CVE-2000-0470?
There is no specific patch for CVE-2000-0470; upgrading to a secure version of the HTTP server is recommended.