First published: Wed Jun 23 2004(Updated: )
DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linksys Befcmu10 | ||
Linksys BEFN2PS4 | ||
Linksys BEFN2PS4 | =1.42.7 | |
Linksys BEFSR11 | =1.40.2 | |
Linksys BEFSR11 | =1.41 | |
Linksys BEFSR11 | =1.42.3 | |
Linksys BEFSR11 | =1.42.7 | |
Linksys BEFSR11 | =1.43 | |
Linksys BEFSR11 | =1.43.3 | |
Linksys BEFSR11 | =1.44 | |
Linksys BEFSR41 | =1.35 | |
Linksys BEFSR41 | =1.36 | |
Linksys BEFSR41 | =1.37 | |
Linksys BEFSR41 | =1.38.5 | |
Linksys BEFSR41 | =1.39 | |
Linksys BEFSR41 | =1.40.2 | |
Linksys BEFSR41 | =1.41 | |
Linksys BEFSR41 | =1.42.3 | |
Linksys BEFSR41 | =1.42.7 | |
Linksys BEFSR41 | =1.43 | |
Linksys BEFSR41 | =1.43.3 | |
Linksys BEFSR41 | =1.44 | |
Linksys BEFSR41 | =1.45.7 | |
Linksys BEFSR41 | ||
Linksys BEFSR81 | ||
Linksys BEFSR81 | =2.42.7.1 | |
Linksys BEFSR81 | =2.44 | |
Linksys BEFSRU31 | =1.40.2 | |
Linksys BEFSRU31 | =1.41 | |
Linksys BEFSRU31 | =1.42.3 | |
Linksys BEFSRU31 | =1.42.7 | |
Linksys BEFSRU31 | =1.43 | |
Linksys BEFSRU31 | =1.43.3 | |
Linksys BEFSRU31 | =1.44 | |
Linksys BEFSX41 | =1.42.7 | |
Linksys BEFSX41 | =1.43 | |
Linksys BEFSX41 | =1.43.3 | |
Linksys BEFSX41 | =1.43.4 | |
Linksys BEFSX41 | =1.44 | |
Linksys BEFSX41 | =1.44.3 | |
Linksys BEFSX41 | =1.45.3 | |
Linksys BEFVP41 | ||
Linksys BEFVP41 | =1.39.64 | |
Linksys BEFVP41 | =1.40.3f | |
Linksys BEFVP41 | =1.40.4 | |
Linksys BEFVP41 | =1.42.7 | |
Linksys RV082 | ||
Linksys WAP55AG | =1.0.7 | |
Cisco Linksys WRT54G Router Firmware | =1.42.3 | |
Cisco Linksys WRT54G Router Firmware | =2.00.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0580 is classified as a medium severity vulnerability due to the risk of sensitive information disclosure.
To fix CVE-2004-0580, upgrade the firmware of affected Linksys routers to the latest version provided by the manufacturer.
CVE-2004-0580 affects Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 routers running firmware version 1.45.7.
CVE-2004-0580 can be exploited by remote attackers sending crafted BOOTP reply packets to obtain previously used buffer contents.
While upgrading firmware is the recommended solution for CVE-2004-0580, disabling the DHCP service can serve as a temporary workaround.