Nortel warns of three VPN Router product flaws

Backdoor user accounts, Web management interfaces and password encryption are susceptible to hacking, vendor says

Nortel has warned of several backdoors, and other flaws, in its VPN and secure routing products that could allow unauthorized remote access to an enterprise network.

User accounts used for diagnostics on Nortel VPN routers (formerly known as Contivity) could be used to gain access to a corporate VPN. In another potential vulnerability, unauthorized remote users could also gain administrative access to a VPN router through a Web interface. A third vulnerability could result in someone cracking users' VPN passwords.

Nortel says it has issued software that fixes these flaws. Product versions affected include all Nortel VPN router models -- 1000, 2000, 3000, 4000 and 5000.

The user account issue, among the three discovered by a German security researcher, involves two user accounts stored in the VPN Router's default directory. The accounts are used for diagnostics of various VPN tunnels types when the router is used in Federal Information Processing Standards encryption mode -- a standard used by government agencies.

"These accounts represent a potential backdoor into the private network from any VPN router," Nortel says in a bulletin.

Web-based management interfaces on VPN routers can also be accessed by unauthorized users by "careful manipulation of the URL" of the router's Web address. Nortel says this could give limited access to some router configuration settings.

Nortel is also warning that the DES key it uses to encrypt all user passwords on its VPN routers are identical. "It is possible -- providing the attacker was able to gain access to the Lightweight Directory Access Protocol store -- to use a brute force attack on the hash of a user password in order to gain network access," Nortel says.

Nortel adds that upgrading to VPN router software versions 6_05.140, 5_05.304 or 5_05.149 fixes the three issues it is reporting. (The upgrade secures the two diagnostic user accounts, closes the vulnerability in the Web manager and adds 3DES encryption to passwords). Software upgrades can be obtained here.

More about: Nortel

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/170/gadwin-geforms/

Gadwin GeForms

GeForms allows you to create your own forms or fill in existing forms electronically. Using GeForms you are provided with sophisticated form design tools which ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia