Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    =?iso-8859-1?Q?Johan_K=F6lhi_=28EAB=29?=
    RE: Ericsson HM220dp ADSL modem Insecure Web Administration Vulne
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: Ericsson HM220dp ADSL modem Insecure Web Administration Vulne

    Hi all,

    Ericsson is working on this issue now. A solution for this problem is =
    on the way, we will come back with more information in next week on =
    this.

    Best regards,

    Johan K=F6lhi
    Ericsson Broadband Access


    -----Original Message-----
    From: Fredrik Bj=F6rk [mailto:Fredrik.Bjork.List@varbergenergi.se]
    Sent: den 13 februari 2003 10:17
    To: bugtraq@securityfocus.com
    Subject: Re: Ericsson HM220dp ADSL modem Insecure Web Administration
    Vulnerability


    At 08:37 2003-02-11 +0100, you wrote:
    >Ericsson HM220dp ADSL modem Insecure Web Administration Vulnerability
    >Discussion:
    >Ericsson HM220dp is a small office enviroment ADSL modem, distributed
    >by many Carriers such as Telecom Italia to thousand users.
    >It may be administered remotely through a number of mechanisms,
    >including a web based interface.
    >Unfortunately, the web interface does not require authentication
    >and does not give the possibility to require it.
    >Unauthorized users accessing the web pages may perform a variety of=20
    >malicious actions.
    >By the way Ericsson forced the modem in "Bridged" mode with a modified =


    >firmware, so the web administration page could not be accessed from=20
    >Internet but "just" from any user of the lan.
    >It is possible that other products of the same series share this=20
    >vulnerabilty.


    Not according to my contacts at Ericsson. The vulnerability is limited =
    to=20
    one batch of 6000 modems delivered to the Italian market, which is bad=20
    enough! The entire 220 series was discontinued in 2001.

    >Solution:
    >Ericsson has been contacted months ago but it's not still providing an =


    >updated firmware version that could prevent the problem ignoring it.


    If Ericsson is completely ignoring this issue, it is not good! However, =
    it=20
    seems that they have provided an upgrade to limit unauthenticated =
    access to=20
    the LAN side of the modem, which could be considered an acceptable =
    solution.

    /Fredrik

  2. #2
    =?iso-8859-1?Q?Johan_K=F6lhi_=28EAB=29?=
    RE: Ericsson HM220dp ADSL modem Insecure Web Administration Vulne
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: Ericsson HM220dp ADSL modem Insecure Web Administration Vulne

    On behalf of Peter Linder, Technical Director, Ericsson Ethernet Broadband Access:


    On February 11 a report was issued on BugTraq related to Ericsson's DSL modem HM 220.
    The initial report included some statements that could be misinterpreted and in order to avoid
    any further confusion on this subject we would like provide the following clarifications.

    Ericsson hm220 is a flexible ADSL modem targeting the residential market.
    For small offices Ericsson recommend hm230 (standard ADSL ), hn310 (ADSL Annex J
    support 3Mbps upstream) and hn800 (SHDSL) which has a feature set that is targeted towards
    the small business customers needs.

    hm220 can be operated in two modes, bridged and routed mode. There is no possibility to remotely
    manage the modem from the WAN side in netither of these two modes. It is possible to perform local
    administration routines from a PC connceted to the LAN side of the modem but that option is restricted
    to the Routed mode only. No such options exist for the products configured for Bridged mode operation.

    Ericsson have scheduled a maintenance release for March 15 for the hm220 software that will eliminate
    any risk for access to the modem being manipulated from the LAN side.

    Any end-user experiencing service interuption through unwanted actions form the PC towards the modem
    can perform a factory reset, which is described in the user manual, which will return all initial installations.

    All Ericsson ADSL modems launched after the hm220 have an increased security feature set for residential
    as well as small business users and the indication that other products in the hm and hn product families
    would be vulnerable is not correct.


    Peter Linder
    Technical Director, Ethernet Broadband Access

    Business Unit Systems
    Ericsson AB
    Phone: + 46 8 719 2974
    e-mail: peter.linder@ericsson.com

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics