3Com HomeConnect Cable Modem External with USB Denial of Service Vulnerability
BID:3366
Info
3Com HomeConnect Cable Modem External with USB Denial of Service Vulnerability
| Bugtraq ID: | 3366 |
| Class: | Unknown |
| CVE: |
CVE-2001-1293 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was reported to BugTraq by Alex S. Harasic <[email protected]>. |
| Vulnerable: |
3Com HomeConnect Cable Modem External with USB |
| Not Vulnerable: | |
Discussion
3Com HomeConnect Cable Modem External with USB Denial of Service Vulnerability
A problem in the firmware running the cable modem could allow a denial of service. It is possible to reboot the modem by connecting to the HTTP service and requesting a long string. This will cause the modem to reset itself.
This problem makes it possible for a remote user to deny service to legimate users of networks serviced by the modem.
This vulnerability is most likely related to BugTraq ID 2721.
It is possible that this behaviour is due to a buffer overflow condition. If this is the case, an the attacker is familiar with the firmware/hardware, it may be possible to force the execution of attacker-supplied instructions.
A problem in the firmware running the cable modem could allow a denial of service. It is possible to reboot the modem by connecting to the HTTP service and requesting a long string. This will cause the modem to reset itself.
This problem makes it possible for a remote user to deny service to legimate users of networks serviced by the modem.
This vulnerability is most likely related to BugTraq ID 2721.
It is possible that this behaviour is due to a buffer overflow condition. If this is the case, an the attacker is familiar with the firmware/hardware, it may be possible to force the execution of attacker-supplied instructions.
Exploit / POC
3Com HomeConnect Cable Modem External with USB Denial of Service Vulnerability
This vulnerability can be exploited using a web browser.
This vulnerability can be exploited using a web browser.
Solution / Fix
3Com HomeConnect Cable Modem External with USB Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
3Com HomeConnect Cable Modem External with USB Denial of Service Vulnerability
References:
References:
- Support for Products (3Com)