Home arrow Knowledge Center arrow Technologies arrow Networking & Internet arrow Hardware / Devices arrow Nortel warns of three VPN Router product flaws
Home
Tools
Knowledge Center
Howto's
Latest Jobs
Latest jobs from IT Contractor Jobs
The latest jobs registered on the IT Contractor Jobs web site.
  • Test Analyst

    - Test Analyst (New Zealand, Auckland - Auckland CBD)

    Test Analyst - Contract A software test Engineer is required for a 6 month contract. Working in the Finance sector and for a...

  • Test Analyst

    - Test Analyst (New Zealand, Auckland - Auckland CBD)

    Test Analyst - Contract A software test Engineer is required for a 6 month contract. Working in the Finance sector and for a high...

  • Senior Infrustructure Engineer

    - Senior Infrustructure Engineer (New Zealand, Wellington - Wellington CBD)

    Senior Infrustructure Engineer - Hourly Rate Contract   I require an experienced Infrastructure Engineer to work in a technological environment that is constantly...


Nortel warns of three VPN Router product flaws PDF Print E-mail

Three potential vulnerabilities affecting all Nortel VPN router models were flagged by the company this week. Nortel has issued patches for all three problems. Nortel adds that upgrading to VPN router software versions 6_05.140, 5_05.304 or 5_05.149 fixes the three issues it is reporting. (The upgrade secures the two diagnostic user accounts, closes the vulnerability in the Web manager and adds 3DES encryption to passwords). Software upgrades can be obtained at Nortel's site.

User accounts used for diagnostics on Nortel VPN routers (formerly known as Contivity) could be used to gain access to a corporate VPN. In another potential vulnerability, unauthorized remote users could also gain administrative access to a VPN router through a Web interface. A third vulnerability could result in someone cracking users' VPN passwords.

Nortel says it has issued software that fixes these flaws. Product versions affected include all Nortel VPN router models (PDF format) -- 1000, 2000, 3000, 4000 and 5000.

The user account issue, among the three discovered by a German security researcher, involves two user accounts stored in the VPN Router's default directory. The accounts are used for diagnostics of various VPN tunnels types when the router is used in Federal Information Processing Standards encryption mode --  a standard used by government agencies.

"These accounts represent a potential backdoor into the private network from any VPN router," Nortel says in a bulletin.

Web-based management interfaces on VPN routers can also be accessed by unauthorized users by "careful manipulation of the URL" of the router's Web address. Nortel says this could give limited access to some router configuration settings.

Nortel is also warning that the DES key it uses to encrypt all user passwords on its VPN routers are identical. "It is possible -- providing the attacker was able to gain access to the Lightweight Directory Access Protocol store -- to use a brute force attack on the hash of a user password in order to gain network access," Nortel says.

 

 
< Prev   Next >
Powered by IT CONTRACTORS and designed by EZPrinting web hosting