CVE-2001-1262: High severity Avaya Argent Office vulnerability
Published Aug 7, 2001
·Updated
Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.
Affected Software
1 affected component
Avaya Argent Office=2.1
Event History
Aug 7, 2001
CVE Published
04:00 AM
May 3, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1262?
CVE-2001-1262 has a medium severity rating due to its potential for authentication bypass.
2
How do I fix CVE-2001-1262?
To fix CVE-2001-1262, update Avaya Argent Office to a version that correctly handles SNMP community strings.
3
What software is affected by CVE-2001-1262?
CVE-2001-1262 specifically affects Avaya Argent Office version 2.1.
4
What type of attack does CVE-2001-1262 enable?
CVE-2001-1262 enables remote attackers to bypass SNMP authentication.
5
Is there a workaround for CVE-2001-1262?
A potential workaround for CVE-2001-1262 is to implement IP filtering to restrict access to the SNMP interface.