First published: Tue Aug 07 2001(Updated: )
Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Argent Office | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1262 has a medium severity rating due to its potential for authentication bypass.
To fix CVE-2001-1262, update Avaya Argent Office to a version that correctly handles SNMP community strings.
CVE-2001-1262 specifically affects Avaya Argent Office version 2.1.
CVE-2001-1262 enables remote attackers to bypass SNMP authentication.
A potential workaround for CVE-2001-1262 is to implement IP filtering to restrict access to the SNMP interface.