3com NBX IP phone system Denial of Service Attack |
|
3com NBX IP phone system Denial of Service Attack Revision Date: April 25, 2003 Reason for Revision: 3com updated nbx firmware to 4_1_21, Add bugtraq-id Systems: 3com NBX IP Phone Call manager, FW Versions through 4_1_21 Discussion: (From 3com's and WindRiver's web site) 3Com® SuperStack® 3 NBX® and 3Com NBX 100 networked telephony solutions offer wide-ranging price/performance alternatives to fit your business needs today and tomorrow. 3Com® SuperStack® 3 NBX® Networked Telephony Solution Delivers robust, full-featured business communications for up to 1500 devices (lines/stations) Ensures high system availability with the Wind River VxWorks real-time operating system (also used in pacemakers and artificial hearts), so server and PC downtime does not impact your telephone service. VxWorks and pSOSystem are the most widely adopted real-time operating systems (RTOSs) in the embedded industry -- for good reason. They are flexible, scalable, reliable, and available on all popular CPU platforms. They are also, by most measures, the fastest RTOSs available today. Exploit: It was possible to make the remote FTP server crash by issuing this command : CEL aaaa[...]aaaa where string is 2048 bytes long. This can be done with netcat, a windows client by telnetting to the nbx server on port 21 or by running the vxworks_ftpd.nasl test in nessus (www.nessus.org) The 3com NBX uses VXWORKS Embedded Real time Operating system and what appears to be their own internal ftp server. This buffer overflow problem seems to be one similar to the AIX ftpd reported in CVE 1999-0789 and has been assigned bugtraq id 6297 By sending a specific string of data to the ftp server, an attacker can not only disable the ftp server, but the integrated web based administrative console and the call manager preventing diagnostics, control and all incoming, outgoing or internal calls. Any calls in progress cannot be disconnected, and in the case of long distance calls, could result in excessive long distance bills and extended loss of use of the phone system. This condition is not recovered without a Hard reboot (power off/on). Since the 3com nbx is based on an embedded Unix operating system (vxworks), an abrupt power off could cause loss of data, including corruption of voice mails in progress or logs. A company who uses the VoIP features for remote locations, and who has the call manager located on the outside of their firewall, or has no firewall can have their voice communications disrupted easily. Even if the company has the call manager located on internal network, people with internal network access can also disrupt communications. We have tested 3com nbx firmware version 4_0_17 (with ftpd version 5.4) and nbx firmware version 4_1_4 and 4_1_21 (ftpd version 5.4.2) and this bug seems to be present in all three systems. 3com Response: VxWorks Response: Solution: Workaround: see "Firewall limits vex VoIP users" at Nwfusion Credit: Additional Information: To test your systems for this vulnerability, you can use Nessus at www.nessus.org. Either update your signatures, or download this nessus signature: vxworks_ftpd.nasl Original copy of this report can be found here Copyright: This security report can be copied and redistributed electronically provided it is not edited and is quoted in its entirety without written consent of SECNAP Network Security, LLC. Additional information or permission may be obtained by contacting SECNAP Network Security at 561-999-5000 |