Global Village modem denial of service (ICMP_Modem_DoS)

About this signature or vulnerability

Proventia Server IPS for Linux technology, RealSecure Desktop, RealSecure Desktop Protector 3.6, Proventia Network IPS, Proventia Network MFS, IBM Security Server Protection for Windows, Proventia-G 1.1 and earlier, Proventia Desktop, Proventia Network IDS, BlackICE Agent for Server, BlackICE PC Protection, BlackICE Server Protection, RealSecure Server Sensor, RealSecure Network, Virtual Server Protection for Vmware:

This signature detects an ICMP packet meant to reset some modems.


Default risk level

Medium risk vulnerability  Medium

Sensors that have this signature

Proventia Server IPS for Linux technology: 1.0, RealSecure Desktop: baseline, RealSecure Desktop Protector 3.6: baseline, Proventia Network IPS: 2.0, Proventia Network MFS: 1.0, IBM Security Server Protection for Windows: 2.1.14.2400, IBM Security Server Protection for Windows: 1.0.914.0, Proventia-G 1.1 and earlier: G Series, Proventia Desktop: 8.0.614.1, Proventia Network IDS: XPU 20.13, BlackICE Agent for Server: 3.6eof, BlackICE PC Protection: 3.6cpa, BlackICE Server Protection: 3.6.cpa, RealSecure Server Sensor: XPU 20.16, RealSecure Network: XPU 20.13, RealSecure Network: XPU 5.12, Virtual Server Protection for Vmware: 1.0, Virtual Server Protection for Vmware: 1.0

Systems affected

Various vendors Any application

Type

Denial of Service

Vulnerability description

Global Village modem AT commands is vulnerable to a denial of service attack. An attacker can send an AT command to a remote computer that responds to commands, such as ctcp, ping, and icmp to cause the modem on the responding computer to execute the received commands. This attack can be performed on any computer with a Global Village modem.

How to remove this vulnerability

No remedy available as of July 9, 2011.

References

Macintouch Web site
Modem Guard Mode/Security Defect
http://www.macintouch.com/modemsecurity.html#workarounds

BUGTRAQ@netspace.org, Sun, 27 Sep 1998 13:52:33 -0400
1+2=3, +++ATH0=Old school DoS
http://www.attrition.org/security/denial/w/mod-ath.dos.html

ISS X-Force
Global Village modem denial of service
http://www.iss.net/security_center/static/3320.php

CVE
CVE-1999-1228
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1228