First published: Fri Oct 12 2007(Updated: )
The 3Com 3CRWER100-75 router with 1.2.10ww software, when remote management is disabled but a web server has been configured, serves a web page to external clients, which might allow remote attackers to obtain information about the router's existence and product details.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
3com 3crwe554g72t | =3crwer100-75 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5420 is evaluated as a medium severity vulnerability due to information disclosure risks.
To fix CVE-2007-5420, ensure that remote management is properly disabled and consider restricting access to the web server.
The potential impacts of CVE-2007-5420 include unauthorized access to information about the router's configuration and product details.
CVE-2007-5420 affects users of the 3Com 3CRWER100-75 router running the 1.2.10ww software version.
Yes, CVE-2007-5420 can be exploited remotely by attackers to gather information about the router.