what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

watchguard.dvcp.txt

watchguard.dvcp.txt
Posted Jul 10, 2002
Authored by Peter Grundl, Andreas Sandor | Site kpmg.dk

Watchguard Firebox Dynamic VPN Configuration Protocol Denial of Service - Malicious users can crash the Dynamic VPN Configuration Protocol service (DVCP) by sending a malformed packet to the listener service on TCP port 4110. Watchguard Firebox firmware v5.x.x is vulnerable.

tags | denial of service, tcp, protocol
SHA-256 | f7fefdb893755ef161385dc353bea35abe34c677710fe9ef1b8f81eb0e3212b7

watchguard.dvcp.txt

Change Mirror Download
--------------------------------------------------------------------

Title: Watchguard Firebox Dynamic VPN Configuration Protocol DoS

BUG-ID: 2002030
Released: 9th Jul 2002
--------------------------------------------------------------------

Problem:
========
A malicious user can crash the Dynamic VPN Configuration Protocol
service (DVCP) by sending a malformed packet to the listener service
on TCP port 4110.


Vulnerable:
===========
- Watchguard Firebox firmware v5.x.x

Not Vulnerable:
===============
- Watchguard Firebox firmware v6.0.b1140


Product Description:
====================
Quoted from the vendor webpage:

"The WatchGuard® Firebox System is a powerful security solution that
gives small and medium sized businesses, central offices, and VPN
hubs integrated firewall protection and VPN support."

"About DVCP
DVCP is a WatchGuard client server protocol that securely transmits
IPSec VPN configuration information to WatchGuard Fireboxes. Network
administrators use WatchGuard software to define each configuration
aspect of the VPN, such as encryption algorithms and how often keys
will be negotiated, then the settings are stored on a centrally
located DVCP Server.When a Firebox is installed and initialized with
software and instructions, a software client on the Firebox contacts
the central DVCP server to obtain IPSec policy information using a
secure protocol."


Details:
========
The DVCP service can be crashed using anywhere between 1 and 400
packets of tab characters, followed by a CRLF. The firewall needs to
be rebooted for the DVCP service to function again.


Vendor URL:
===========
You can visit the vendor webpage here: http://www.watchguard.com


Vendor response:
================
The vendor was notified on the 8th of May, 2002. On the 23rd of
May, 2002 the vendor notified us that the issue would be resolved
in the next version (6.x). On the 9th of July we verified that
the problem was resolved in the new firmware version.


Corrective action:
==================
Upgrade to firmware version 6.x, available at the livesecurity
website. If you are not a subscriber to the livesecurity service,
please contact Watchguard support further assistance.



Authors:
Andreas Sandor (asandor@kpmg.dk)
Peter Gründl (pgrundl@kpmg.dk)

--------------------------------------------------------------------
KPMG is not responsible for the misuse of the information we provide
through our security advisories. These advisories are a service to
the professional security community. In no event shall KPMG be lia-
ble for any consequences whatsoever arising out of or in connection
with the use or spread of this information.
--------------------------------------------------------------------

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close