CVE-2007-2333
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- nortel/contivity · nortel/vpn router 5000 · nortel/vpn router portfolio
- Source
- cve@mitre.org
References
- http://osvdb.org/35055
- http://secunia.com/advisories/24962Patch, Vendor Advisory
- http://www.securityfocus.com/bid/23562
- http://www.securitytracker.com/id?1017943
- http://www.vupen.com/english/advisories/2007/1464
- http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=567877&RenditionID=&poid=nullPatch
- http://osvdb.org/35055
- http://secunia.com/advisories/24962Patch, Vendor Advisory
- http://www.securityfocus.com/bid/23562
- http://www.securitytracker.com/id?1017943
- http://www.vupen.com/english/advisories/2007/1464
- http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=567877&RenditionID=&poid=nullPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.