Secunia Security Advisory - Shawn Merdinger has reported a weakness in ZyXEL P-2000W_v2 VoIP Wi-Fi Phone, which can be exploited by malicious people to disclose system information and potentially cause a DoS (Denial of Service).
f38f89048ddae20d1f43686a3ec6680b7dab3090a3568cdb92e6253898e8ba12
TITLE:
ZyXEL P-2000W_v2 VoIP Wi-Fi Phone Information Disclosure
SECUNIA ADVISORY ID:
SA18511
VERIFY ADVISORY:
http://secunia.com/advisories/18511/
CRITICAL:
Not critical
IMPACT:
Exposure of system information, DoS
WHERE:
>From local network
OPERATING SYSTEM:
ZyXEL P-2000W_v2 VoIP Wi-Fi Phone
http://secunia.com/product/6846/
DESCRIPTION:
Shawn Merdinger has reported a weakness in ZyXEL P-2000W_v2 VoIP
Wi-Fi Phone, which can be exploited by malicious people to disclose
system information and potentially cause a DoS (Denial of Service).
The weakness is caused due to the phone allowing connections to an
undocumented service on port 9090/udp. This can be exploited to
disclose the MAC address and the software version of the phone.
This may also be exploited to cause a DoS on an affected phone.
The weakness has been reported in firmware version WV.00.02. Other
versions may also be affected.
SOLUTION:
Restrict use to within trusted networks only.
PROVIDED AND/OR DISCOVERED BY:
Shawn Merdinger
ORIGINAL ADVISORY:
http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041438.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------