|
Cisco Wireless IP Phone Two Vulnerabilities
|
|
Secunia Advisory:
|
SA17604
|
|
|
Release Date:
|
2005-11-17
|
|
Last Update:
|
2005-12-07
|
|
Popularity:
|
6,971 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Manipulation of data Exposure of sensitive information DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Cisco IP Phone 7900 Series
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2005-3803 CVE-2005-3804
|
|
Description: Two vulnerabilities have been reported in Cisco Wireless IP Phone, which can be exploited by malicious people to gain access to potentially sensitive information, to modify certain information, and to cause a DoS (Denial of Service).
1) The SNMP service that runs on the IP phone uses fixed read-only and read-write community strings of "public" and "private", which cannot be changed by the user. This can be exploited to retrieve and modify the device configuration, including stored user data such as phone book entries by sending SNMP GetRequest or SetRequest to phone.
2) The IP phone listens on port 17185/udp to allow connections from the VxWorks debugger. This may be exploit to collect debugging information or to cause a DoS on the device.
The vulnerabilities have been reported in Cisco 7920 Wireless IP Phone with firmware version 2.0 and prior.
Solution: Apply firmware update.
http://www.cisco.com/warp/public/707/cisco-sa-20051116-7920.shtml#software
Provided and/or discovered by: Reported by vendor.
Changelog: 2005-12-07: Added CVE references.
Original Advisory: Cisco:
http://www.cisco.com/warp/public/707/cisco-sa-20051116-7920.shtml
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|