Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers to access the administration interface and change the device configuration via certain requests. The vendor has addressed this issue with the following product update: http://www130.nortelnetworks.com/go/main.jsp?cscatBLTNDETAIL&DocumentOID567877&RenditionID&poidnull
Publication date: Fri, 27 Apr 2007 21:19:00 +0000