Unisys Clearpath MCP Portscan Denial Of Service Vulnerability
BID:5863
Info
Unisys Clearpath MCP Portscan Denial Of Service Vulnerability
| Bugtraq ID: | 5863 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2002 12:00AM |
| Updated: | Oct 02 2002 12:00AM |
| Credit: | Discovery credited to Jonathan G. Lampe. |
| Vulnerable: |
Unisys Clearpath |
| Not Vulnerable: | |
Discussion
Unisys Clearpath MCP Portscan Denial Of Service Vulnerability
A denial of service vulnerability has been discovered in Unisys Clearpath mainframes.
Reportedly, it is possible to crash a Unisys system by initiating a typical port scan with the nmap or similar tools.
It has been determined that the dynamic initialization feature in the ClearPath MCP environment is the cause of the high cpu utilization and excessive log entries.
A denial of service vulnerability has been discovered in Unisys Clearpath mainframes.
Reportedly, it is possible to crash a Unisys system by initiating a typical port scan with the nmap or similar tools.
It has been determined that the dynamic initialization feature in the ClearPath MCP environment is the cause of the high cpu utilization and excessive log entries.
Exploit / POC
Unisys Clearpath MCP Portscan Denial Of Service Vulnerability
This issue may be exploited with nmap or similar portscanning utilities.
This issue may be exploited with nmap or similar portscanning utilities.
Solution / Fix
Unisys Clearpath MCP Portscan Denial Of Service Vulnerability
Solution:
The vendor has confirmed this issue and has supplied the following solution:
The customer can either disable the dynamic initialization feature for those ports which are not in use on the system or place a third-party product (like SYNDefender) in front of the ClearPath.
Solution:
The vendor has confirmed this issue and has supplied the following solution:
The customer can either disable the dynamic initialization feature for those ports which are not in use on the system or place a third-party product (like SYNDefender) in front of the ClearPath.
References
Unisys Clearpath MCP Portscan Denial Of Service Vulnerability
References:
References: