OSVDB ID: 22516

Title: ZyXEL P-2000W_v2 VoIP Wi-Fi Phone UDP Port 9090 Information Disclosure

Info

Disclosure

Jan 16, 2006

Discovery

Dec 07, 2005

Dates

Exploit

Jan 16, 2006

Solution

Unknown

Description

ZyXEL P-2000W_v2 VoIP Wi-Fi Phone contains a flaw that may lead to an unauthorized information disclosure.  An undocumented service is running on UDP port 9090 and some information about the device could be obtained from it : - Software/Firmware version - MAC address This will disclose information about the phone device resulting in a loss of confidentiality.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Unknown

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

ZyXEL Communications Corporation

ZyXel P2000W (Version 2) VoIP wireless phone

WV.00.02

References

Credit

  • Shawn Merdinger - shawnmergmail.com -


Direct URL: http://osvdb.org/22516