First published: Fri Apr 27 2007(Updated: )
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel Vpn Router Portfolio | ||
Nortel Vpn Router 5000 | ||
Nortel Contivity | =2000_vpn_switch | |
Nortel Contivity | =1000_vpn_switch | |
Nortel Contivity | =4000_vpn_switch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2333 is considered a critical vulnerability due to the potential for remote access to private networks.
To mitigate CVE-2007-2333, you should upgrade the Nortel VPN Router firmware to a version newer than 5_05.149 or 6.x newer than 6_05.140.
CVE-2007-2333 affects the Nortel VPN Router Portfolio, including models 1000, 2000, 4000, and 5000.
Yes, CVE-2007-2333 exposes default accounts in the LDAP template that can be exploited by remote attackers.
CVE-2007-2333 can be exploited for unauthorized access and potentially allow attackers to compromise private network security.