CVE-2006-0374
Last modified
CVE-2006-0374 is a vulnerability of currently unknown severity. Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).. EPSS estimates a 1.65% chance of exploitation in the next 30 days.
Description
Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Advantage Century Telecommunication | P202s | 1.01.21_firmware_1.1.21 |
References
- http://secunia.com/advisories/18514Vendor Advisory
- http://secunia.com/advisories/18514Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0374?
How severe is CVE-2006-0374?
How do I fix CVE-2006-0374?
Are you affected by CVE-2006-0374?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
