PT-2002-2689 · Com21 · Com21 Doxport 1100 Series
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1968
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Com21 DOXport 1100 series cable modem versions 2.1.1.106 through 2.1.1.108.003
Description
The issue allows local users to modify the configuration of the modem by setting up a malicious TFTP server on the internal network, which the modem connects to in order to download a DOCSIS configuration file.
Recommendations
For versions 2.1.1.106 through 2.1.1.108.003, restrict access to the internal network to prevent malicious TFTP servers from being set up.
As a temporary workaround, consider disabling the TFTP client functionality until a patch is available.
Avoid using the TFTP protocol for downloading configuration files from untrusted sources until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Com21 Doxport 1100 Series