Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/1/202344 | vendor advisory mailing list exploit |
http://www.iss.net/security_center/static/6955.php | vdb entry vendor advisory |