XFIT/S data denial of service

xfits-data-dos (25567) The risk level is classified as MediumMedium Risk

Description:

Hitachi XFIT/S, HI-UX/WE2, XFIT/S/JCA, HI-UX/WE2, XFIT/S/ZGN, HI-UX/WE2, and XFIT/S ZENGIN TCP/IP Procedure are vulnerable to a denial of service. When receiving unexpected data it is possible for transfer requests to be rejected or the server process to stop responding.


Consequences:

Denial of Service

Remedy:

Apply the patch for this vulnerability as listed in the Hitachi Software Vulnerability Information Advisory HS06-004. See References.

References:

  • Hitachi Software Vulnerability Information HS06-004: Issue of File Transfer Impossibility in XFIT/S.
  • BID-17329: XFIT/S Unspecified Denial of Service Vulnerability
  • CVE-2006-1609: Unspecified vulnerability in Hitachi XFIT/S, XFIT/S/JCA, XFIT/S/ZGN, and XFIT/S ZENGIN TCP/IP Procedure allows remote attackers to cause a denial of service (server process and transfer control process stop) when the products receive data unexpectedly.
  • OSVDB ID: 24309: XFIT/S File Transfer Unspecified Malformed Data DoS
  • SA19472: XFIT/S File Transfer Denial of Service Vulnerability

Platforms Affected:

  • Hitachi XFIT/S 01-00 - 01-00-/A
  • Hitachi XFIT/S 01-08 - 01/13/I
  • Hitachi XFIT/S Zengin TCP/IP Procedure 01-00 - 01-00-/D
  • Hitachi XFIT/S Zengin TCP/IP Procedure 01-00 - 01-02-/C
  • Hitachi XFIT/S/JCA 01-00 - 01-00-/A
  • Hitachi XFIT/S/JCA 01-03 - 01-05-/E
  • Hitachi XFIT/S/ZGN 01-00 - 01-00-/B
  • Hitachi XFIT/S/ZGN 01-02-/F-01-04-/D

Reported:

Mar 31, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page