{"api_version":"1","generated_at":"2026-07-23T09:19:09+00:00","cve":"CVE-2006-0374","urls":{"html":"https://cve.report/CVE-2006-0374","api":"https://cve.report/api/cve/CVE-2006-0374.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0374","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0374"},"summary":{"title":"CVE-2006-0374","description":"Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-22 20:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"[Full-disclosure] ACT P202S VoIP wireless phone multiple\n\tundocumented ports/services","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16288","name":"http://www.securityfocus.com/bid/16288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ACT P202S VOIP WIFI Phones Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24149","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18514","name":"http://secunia.com/advisories/18514","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ACT WLAN Phone P202S Multiple Security Issues - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0374","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0374","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"374","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"advantage_century_telecommunication","cpe5":"p202s","cpe6":"1.01.21_firmware_1.1.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"374","cve":"CVE-2006-0374","epss":"0.010680000","percentile":"0.777530000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:34:14.615Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"act-p202s-default-port(24149)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24149"},{"name":"18514","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18514"},{"name":"20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html"},{"name":"16288","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16288"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"act-p202s-default-port(24149)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24149"},{"name":"18514","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18514"},{"name":"20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html"},{"name":"16288","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16288"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0374","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"act-p202s-default-port(24149)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24149"},{"name":"18514","refsource":"SECUNIA","url":"http://secunia.com/advisories/18514"},{"name":"20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html"},{"name":"16288","refsource":"BID","url":"http://www.securityfocus.com/bid/16288"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0374","datePublished":"2006-01-22T20:00:00.000Z","dateReserved":"2006-01-22T00:00:00.000Z","dateUpdated":"2024-08-07T16:34:14.615Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-22 20:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:advantage_century_telecommunication:p202s:1.01.21_firmware_1.1.21:*:*:*:*:*:*:*","matchCriteriaId":"6B7D6FEB-0F92-4D2D-89E9-D9766F15ECE8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"374","Ordinal":"1","Title":"CVE-2006-0374","CVE":"CVE-2006-0374","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"374","Ordinal":"1","NoteData":"Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).","Type":"Description","Title":"CVE-2006-0374"},{"CveYear":"2006","CveId":"374","Ordinal":"2","NoteData":"2006-01-22","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"374","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}