Global Village modem denial of service (ICMP_Modem_DoS)

About this signature or vulnerability

Proventia Server IPS for Linux technology, RealSecure Network, Proventia Network MFS, Proventia-G 1.1 and earlier, Proventia Network IPS, Proventia Desktop, Proventia Server IPS for Microsoft Windows technology, BlackICE Server Protection, BlackICE PC Protection, BlackICE Agent for Server, RealSecure Server Sensor:

This signature detects an ICMP packet meant to reset some modems.


Default risk level

Medium risk vulnerability  Medium

Sensors that have this signature

Proventia Server IPS for Linux technology: 1.0, RealSecure Network: XPU 20.13, RealSecure Network: XPU 5.12, Proventia Network MFS: 1.0, Proventia-G 1.1 and earlier: G Series, Proventia Network IPS: 2.0, Proventia Desktop: 8.0.614.1, Proventia Server IPS for Microsoft Windows technology: 1.0.914.0, BlackICE Server Protection: 3.6.cpa, BlackICE PC Protection: 3.6cpa, BlackICE Agent for Server: 3.6eof, RealSecure Server Sensor: XPU 20.16

Systems affected

Various vendors Any application

Type

Denial of Service

Vulnerability description

Global Village modem AT commands is vulnerable to a denial of service attack. An attacker can send an AT command to a remote computer that responds to commands, such as ctcp, ping, and icmp to cause the modem on the responding computer to execute the received commands. This attack can be performed on any computer with a Global Village modem.

How to remove this vulnerability

No remedy available as of November 29, 2008.

References

Macintouch Web site
Modem Guard Mode/Security Defect
http://www.macintouch.com/modemsecurity.html#workarounds

BUGTRAQ@netspace.org, Sun, 27 Sep 1998 13:52:33 -0400
1+2=3, +++ATH0=Old school DoS
http://www.attrition.org/security/denial/w/mod-ath.dos.html

ISS X-Force
Global Village modem denial of service
http://www.iss.net/security_center/static/3320.php

CVE
CVE-1999-1228
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1228