PT-2009-3052 · Sony Ericsson · Sony Ericsson K660I+6
Published
2009-02-03
·
Updated
2018-10-11
·
CVE-2009-0396
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Sony Ericsson W910i
Sony Ericsson W660i
Sony Ericsson K618i
Sony Ericsson K610i
Sony Ericsson Z610i
Sony Ericsson K810i
Sony Ericsson K660i
Sony Ericsson W880i
Sony Ericsson K530i
Description
The issue allows remote attackers to cause a denial of service, resulting in a device reboot or hang-up. This can be achieved by sending a malformed WAP Push packet to either SMS or UDP port 2948.
Recommendations
For Sony Ericsson W910i, consider restricting access to UDP port 2948 as a temporary workaround.
For Sony Ericsson W660i, avoid using SMS services until the issue is resolved.
For Sony Ericsson K618i, restrict incoming WAP Push packets to minimize the risk of exploitation.
For Sony Ericsson K610i, consider disabling the SMS functionality until a fix is available.
For Sony Ericsson Z610i, restrict access to UDP port 2948 to prevent denial of service attacks.
For Sony Ericsson K810i, avoid using services that rely on WAP Push packets until the issue is resolved.
For Sony Ericsson K660i, consider implementing firewall rules to block incoming traffic on UDP port 2948.
For Sony Ericsson W880i, restrict incoming SMS traffic to minimize the risk of exploitation.
For Sony Ericsson K530i, consider disabling the WAP Push functionality until a fix is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sony Ericsson K530I
Sony Ericsson K610I
Sony Ericsson K618I
Sony Ericsson K660I
Sony Ericsson K810I
Sony Ericsson W880I
Sony Ericsson W910I