CVE-2013-4708

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
01/10/2013
Last modified:
11/04/2025

Description

The PPP Access Concentrator (PPPAC) in Internet Initiative Japan Inc. SEIL/x86 1.00 through 2.80, SEIL/X1 1.00 through 4.30, SEIL/X2 1.00 through 4.30, SEIL/B1 1.00 through 4.30, SEIL/Turbo 1.80 through 2.15, and SEIL/neu 2FE Plus 1.80 through 2.15 generates predictable random numbers, which allows remote attackers to bypass RADIUS authentication by sniffing RADIUS traffic.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:iij:seil\%2fx1_firmware:1.00:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fx1_firmware:4.30:*:*:*:*:*:*:*
cpe:2.3:h:iij:seil\/x1:*:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fb1_firmware:1.00:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fb1_firmware:4.30:*:*:*:*:*:*:*
cpe:2.3:h:iij:seil\/b1:*:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fx2_firmware:1.00:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fx2_firmware:4.30:*:*:*:*:*:*:*
cpe:2.3:h:iij:seil\/x2:*:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fx86_firmware:1.00:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fx86_firmware:2.80:*:*:*:*:*:*:*
cpe:2.3:h:iij:seil\/x86:*:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fturbo_firmware:1.80:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fturbo_firmware:2.05:*:*:*:*:*:*:*
cpe:2.3:o:iij:seil\%2fturbo_firmware:2.15:*:*:*:*:*:*:*