Lucent's vulnerability profile centers on telecommunications and network access infrastructure, particularly its RADIUS server, Ascend routing platforms, and access-point service products that were integral to enterprise and service-provider networks. Its disclosed vulnerabilities frequently acquire public exploit code, reflecting the security-sensitive nature of authentication and routing components in networked environments. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lucent over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0236HIGH Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the Vs | May 29, 2002 | 7.5 | 31 | NO | YES |
CVE-2002-2149MEDIUM Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTTP request to the administrativ | Dec 31, 2002 | 5.0 | 28 | NO | YES |
CVE-2001-0534HIGH Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands. | Jul 21, 2001 | 10.0 | 27 | NO | NO |
CVE-1999-0060MEDIUM Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool. | Mar 16, 1998 | 5.0 | 27 | NO | YES |
CVE-2001-1376HIGH Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via share | Mar 4, 2002 | 7.5 | 22 | NO | NO |
CVE-2001-1377MEDIUM Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via | Mar 4, 2002 | 5.0 | 21 | NO | NO |
CVE-2001-1081HIGH Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via f | Jul 6, 2001 | 7.5 | 20 | NO | NO |
CVE-2002-2148MEDIUM Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as h | Dec 31, 2002 | 5.0 | 19 | NO | NO |
CVE-2001-0618HIGH Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occu | Aug 2, 2001 | 7.5 | 19 | NO | NO |
CVE-2001-0619HIGH The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The 'Network Name' or SSID, which is used as a shar | Aug 2, 2001 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lucent.
Media articles that mention a CVE ID that affects a product developed by Lucent — matched by CVE ID, not by vendor name.