First published: Thu May 15 2003(Updated: )
3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3com 3cp4144 | =1.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0291 is considered to be a moderate severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2003-0291, it is recommended to upgrade the 3com OfficeConnect Remote 812 ADSL Router to a patched version that properly clears memory from DHCP responses.
Attackers can exploit CVE-2003-0291 by sniffing DHCP packets to capture sensitive data from previous HTTP requests.
CVE-2003-0291 specifically affects the 3com OfficeConnect Remote 812 ADSL Router running version 1.1.7.
A firewall may provide some level of protection, but it cannot mitigate the information disclosure risks associated with CVE-2003-0291.