CVE-2004-0580: Medium severity linksys befsr11 vulnerability
DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0580?
CVE-2004-0580 is classified as a medium severity vulnerability due to the risk of sensitive information disclosure.
How do I fix CVE-2004-0580?
To fix CVE-2004-0580, upgrade the firmware of affected Linksys routers to the latest version provided by the manufacturer.
Which Linksys models are affected by CVE-2004-0580?
CVE-2004-0580 affects Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 routers running firmware version 1.45.7.
What is the exploit scenario for CVE-2004-0580?
CVE-2004-0580 can be exploited by remote attackers sending crafted BOOTP reply packets to obtain previously used buffer contents.
Is there a workaround for CVE-2004-0580?
While upgrading firmware is the recommended solution for CVE-2004-0580, disabling the DHCP service can serve as a temporary workaround.