The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.kb.cert.org/vuls/id/458007 | US Government Resource | 
| http://www.kb.cert.org/vuls/id/BLUU-997M5B | US Government Resource | 
| http://www.securityfocus.com/bid/61169 | |
| http://www.kb.cert.org/vuls/id/458007 | US Government Resource | 
| http://www.kb.cert.org/vuls/id/BLUU-997M5B | US Government Resource | 
| http://www.securityfocus.com/bid/61169 | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 01:56
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.kb.cert.org/vuls/id/458007 - US Government Resource | |
| References | () http://www.kb.cert.org/vuls/id/BLUU-997M5B - US Government Resource | |
| References | () http://www.securityfocus.com/bid/61169 - | 
Information
                Published : 2013-07-18 16:51
Updated : 2025-04-11 00:51
NVD link : CVE-2013-4877
Mitre link : CVE-2013-4877
CVE.ORG link : CVE-2013-4877
JSON object : View
Products Affected
                verizon
- wireless_network_extender
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
