SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-3253

Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000 after 2.4.11 and before 3.1, use a static WEP key of…

HIGH 7.5EPSS 1.80%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000 after 2.4.11 and before 3.1, use a static WEP key of "12345", which allows remote attackers to bypass authentication.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.80% probability · 77th percentile
CISA KEV
Not listed
Affected
avaya/wireless ap-3 · avaya/wireless ap-4 · avaya/wireless ap-5 · avaya/wireless ap-6 · avaya/wireless ap-7 · avaya/wireless ap-8 · proxim/ap-2000 · proxim/ap-4000 · proxim/ap-600 · proxim/ap-700
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.