mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-08 11:36:33 +00:00
19 lines
771 B
Markdown
19 lines
771 B
Markdown
![]() |
### [CVE-2013-4877](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4877)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- http://www.kb.cert.org/vuls/id/458007
|
||
|
- http://www.kb.cert.org/vuls/id/BLUU-997M5B
|
||
|
|
||
|
#### Github
|
||
|
No PoCs found on GitHub currently.
|
||
|
|