CVE-2002-2149: Buffer Overflow
Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTTP request to the administrative interface.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the administrative HTTP interface (management web port) of Lucent Access Point Service Router 1500, Lucent Access Point Service Router 300, and Lucent Access Point Service Router 600 to trusted IP addresses via firewall rules or ACLs; block or deny access from untrusted networks (for example, the Internet) to the device management interface.
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2149?
CVE-2002-2149 has a high severity due to its ability to cause a denial of service by rebooting affected models.
How do I fix CVE-2002-2149?
To fix CVE-2002-2149, update the firmware of the Lucent Access Point Service Routers to the latest version recommended by the vendor.
Which devices are affected by CVE-2002-2149?
CVE-2002-2149 affects Lucent Access Point Service Router models 300, 600, and 1500.
What kind of attack does CVE-2002-2149 involve?
CVE-2002-2149 involves a buffer overflow attack that is triggered by sending a long HTTP request to the administrative interface.
Is there a workaround for CVE-2002-2149?
A potential workaround for CVE-2002-2149 includes restricting access to the administrative interface to trusted IP addresses only.