Menu

Database

Open UDP Debug Port in Cisco 7920 Wireless IP Phone

WVE ID: WVE-2006-0009

Type: Vulnerability

Status: Candidate

Classification:
Denial of Service
Information Disclosure

Description:
The Cisco 7920 802.11b VOIP contains an open UDP port used for remote debugging.

Discussion:
The Cisco 7920 is vulnerable to remote attack via an open UDP port. The device is shipped with UDP port 17185 open. This port is used by the VxWorks remote debugger to allow developers to debug the device remotely from a development machine. As such, it provides access to a great deal of information contained in the device.

Because of this it may be possible for an attacker to remotely gather information from the device or mount a denial of service (DoS) attack against the device by issuing debugging commands.

All firmware versions 2.0 and less are vulnerable. Cisco has provided a fix for this issue which can be obtained by following the information available in the cited advisory.

Credits
Author: Shawn Merdinger (shawnmer@gmail.com) : None

References
URL: http://www.cisco.com/warp/public/707/cisco-sa-20051116-7920.shtml

Released: 2005-11-16

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Mon Jan 30 13:59:26 -0800 2006

Candidate Date: Wed Feb 01 10:22:20 -0800 2006


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...