CVE-2001-1425
Last modified
CVE-2001-1425 is a vulnerability of currently unknown severity. The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.. EPSS estimates a 3.74% chance of exploitation in the next 30 days.
Description
The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alcatel | Speed Touch Home | khdsaa.108 |
| Alcatel | Speed Touch Home | khdsaa.132 |
| Alcatel | Speed Touch Home | khdsaa.133 |
| Alcatel | Speed Touch Home | khdsaa.134 |
References
- http://www.cert.org/advisories/CA-2001-08.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/243592US Government Resource
- http://www.securityfocus.com/bid/2568Vendor Advisory
- http://www.cert.org/advisories/CA-2001-08.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/243592US Government Resource
- http://www.securityfocus.com/bid/2568Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-1425?
How severe is CVE-2001-1425?
How do I fix CVE-2001-1425?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-1419AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remo…
- CVE-2001-1420AOL Instant Messenger (AIM) 4.7 allows remote attackers to c…
- CVE-2001-1421AOL Instant Messenger (AIM) 4.7 and earlier allows remote at…
- CVE-2001-1422WinVNC 3.3.3 and earlier generates the same challenge string…
- CVE-2001-1423Advanced Poll before 1.61, when using a flat file database, …
- CVE-2001-1424Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, …
- CVE-2001-1426Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.1…
- CVE-2001-1427Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1…
- CVE-2001-1428The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip ar…
- CVE-2001-1429Buffer overflow in mcedit in Midnight Commander 4.5.1 allows…
- CVE-2001-1430Cayman 3220-H DSL Router 1.0 ship without a password set, wh…
- CVE-2001-1431Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWal…
Are you affected by CVE-2001-1425?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
