81974 : APCO P25 Protocol “inhibit” Extended Function Command (XFC) Remote DoS
Printer | http://osvdb.org/81974 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
2 350 about 1 year ago 10 months ago 7 times 70%

Timeline

Disclosure Date
2011-09-10

Description

The APCO P25 protocol contains a flaw that may allow a remote denial of service. The issue is triggered when an unauthenticated “inhibit” extended function command (XFC) is directed towards a legitimate radio device and causing them to become disabled, resulting in the loss of availability of a radio device.

Classification

Location: Remote / Network Access, Wireless Vector
Attack Type: Denial of Service
Impact: Loss of Availability
Solution: Workaround
Exploit: Exploit Public

Solution

Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the following workaround: Some manufacturers allow for radios to be configured to ignore inhibit commands. This is often a configuration option that can be set for each MR using the equipment’s programming interface. Allowing inhibit to be disabled is intended to mitigate the threat of DoS attacks but does so at the cost of negating the anti-theft measure.

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete

CVSSv2 Score

NVD does not currently have a CVSSv2 score assigned.

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use