4.3
CVSSv2

CVE-2011-0887

Published: 08/02/2011 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware prior to 1.4.0.49.2 uses predictable session IDs based on time values, which makes it easier for remote malicious users to hijack sessions via a brute-force attack on the userid cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

smc_networks smcd3g-ccr

smc_networks smcd3g-ccr_firmware 1.4.0.42

Exploits

Trustwave's SpiderLabs Security Advisory TWSL2011-002: Vulnerabilities in Comcast DOCSIS 30 Business Gateways (D3G-CCR) wwwtrustwavecom/spiderlabs/advisories/TWSL2011-002txt Published: 2011-02-04 Version: 10 Vendor: Comcast (comcastcom) Product: Comcast DOCSIS 30 Business Gateway - D3G-CCR Version affected: Versions prior ...
Comcast DOCSIS 30 Business Gateways suffer from static credential, multiple cross site request forgery, and weak session management vulnerabilities Versions prior to 140492 are affected ...