PT-2002-2689 · Com21 · Com21 Doxport 1100 Series

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1968

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Com21 DOXport 1100 series cable modem versions 2.1.1.106 through 2.1.1.108.003
Description The issue allows local users to modify the configuration of the modem by setting up a malicious TFTP server on the internal network, which the modem connects to in order to download a DOCSIS configuration file.
Recommendations For versions 2.1.1.106 through 2.1.1.108.003, restrict access to the internal network to prevent malicious TFTP servers from being set up. As a temporary workaround, consider disabling the TFTP client functionality until a patch is available. Avoid using the TFTP protocol for downloading configuration files from untrusted sources until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1968

Affected Products

Com21 Doxport 1100 Series