CVE-2006-0374 Information

Description

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available which (1) might allow remote attackers to obtain sensitive information such as memory contents and internal operating-system data by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185 (2) reflect network data using echo (TCP 7) or (3) gain access without authentication using rlogin (TCP 513).

Reference

http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html http://secunia.com/advisories/18514 http://www.securityfocus.com/bid/16288 https://exchange.xforce.ibmcloud.com/vulnerabilities/24149

Share on: