PT-2009-3052 · Sony Ericsson · Sony Ericsson K660I+6

Published

2009-02-03

·

Updated

2018-10-11

·

CVE-2009-0396

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Sony Ericsson W910i Sony Ericsson W660i Sony Ericsson K618i Sony Ericsson K610i Sony Ericsson Z610i Sony Ericsson K810i Sony Ericsson K660i Sony Ericsson W880i Sony Ericsson K530i
Description The issue allows remote attackers to cause a denial of service, resulting in a device reboot or hang-up. This can be achieved by sending a malformed WAP Push packet to either SMS or UDP port 2948.
Recommendations For Sony Ericsson W910i, consider restricting access to UDP port 2948 as a temporary workaround. For Sony Ericsson W660i, avoid using SMS services until the issue is resolved. For Sony Ericsson K618i, restrict incoming WAP Push packets to minimize the risk of exploitation. For Sony Ericsson K610i, consider disabling the SMS functionality until a fix is available. For Sony Ericsson Z610i, restrict access to UDP port 2948 to prevent denial of service attacks. For Sony Ericsson K810i, avoid using services that rely on WAP Push packets until the issue is resolved. For Sony Ericsson K660i, consider implementing firewall rules to block incoming traffic on UDP port 2948. For Sony Ericsson W880i, restrict incoming SMS traffic to minimize the risk of exploitation. For Sony Ericsson K530i, consider disabling the WAP Push functionality until a fix is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0396

Affected Products

Sony Ericsson K530I
Sony Ericsson K610I
Sony Ericsson K618I
Sony Ericsson K660I
Sony Ericsson K810I
Sony Ericsson W880I
Sony Ericsson W910I