|
[Japanese]
|
JVNDB-2012-000051
|
Logitec LAN-W300N/R series fails to restrict access permissions
|
Logitec LAN-W300N/R series contain an issue where access permissions are not restricted.
The LAN-W300N/R series are wireless LAN routers. Logitec LAN-W300N/R series contain an issue where access permissions are not restricted.
Jin Sawada, Keisuke Okazaki, Naoto Katsumi of Security Engineering Laboratory, IT Security Center(ISEC), IPA reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
Base Metrics:
7.5 (High)
[IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
|
|
|
Logitec Corp.
- LAN-W300N/R firmware version 2.17
|
For more information, refer to the developer's website.
|
An attacker that can access the product may log in with administrative privileges. As a result, settings may be changed or altered by the attacker who logged in to LAN-W300N/R.
|
[Update the software]
Update to the latest version according to the information provided by the developer.
|
Logitec Corp.
|
- Permissions(CWE-264) [IPA Evaluation]
|
- CVE-2012-1250
|
- JVN : JVN#85934986
- National Vulnerability Database (NVD) : CVE-2012-1250
- IPA SECURITY ALERTS : Security Alert for Vulnerability in LAN-W300N/R Series
- JPCERT REPORT : JPCERT-AT-2012-0017 (Japanese Only)
- Related document : OCN [Important] Security Notice for Logitec wireless LAN router (Japanese Only)
|
[2012/05/25]
Web page was published
|