<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Router Vulnerabilities Found in Tech Help - Software/Hardware etc</title>
    <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612761#M85134</link>
    <description>&lt;P&gt;Hi - I've used a Trend Micro scanner and my Sagemcom router has the following vulnerabilities:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-SSLv2 Drown Attack Vulnerability&lt;/P&gt;&lt;P&gt;-SSL Poodle Attack Vulnerability&lt;/P&gt;&lt;P&gt;-Device has an open port which may be access from the internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I fix these please?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Feb 2019 14:46:44 GMT</pubDate>
    <dc:creator>pascoej</dc:creator>
    <dc:date>2019-02-11T14:46:44Z</dc:date>
    <item>
      <title>Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612761#M85134</link>
      <description>&lt;P&gt;Hi - I've used a Trend Micro scanner and my Sagemcom router has the following vulnerabilities:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-SSLv2 Drown Attack Vulnerability&lt;/P&gt;&lt;P&gt;-SSL Poodle Attack Vulnerability&lt;/P&gt;&lt;P&gt;-Device has an open port which may be access from the internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I fix these please?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 14:46:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612761#M85134</guid>
      <dc:creator>pascoej</dc:creator>
      <dc:date>2019-02-11T14:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612812#M85135</link>
      <description>Buy your own probably; you are unable to do any s/ware updates to any PN supplied (+ locked) router.</description>
      <pubDate>Mon, 11 Feb 2019 17:04:36 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612812#M85135</guid>
      <dc:creator>Gel</dc:creator>
      <dc:date>2019-02-11T17:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612875#M85137</link>
      <description>&lt;P&gt;Hi - I need to find out if the latest firmware has fixed these vulnerabilities and when it was last updated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Feb 2019 21:35:43 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612875#M85137</guid>
      <dc:creator>pascoej</dc:creator>
      <dc:date>2019-02-11T21:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612890#M85138</link>
      <description>&lt;P&gt;Login to the router, that will show you the last update date.&lt;/P&gt;
&lt;P&gt;As for fixes..&amp;nbsp;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/14"&gt;@bobpullen&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 00:54:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612890#M85138</guid>
      <dc:creator>7up</dc:creator>
      <dc:date>2019-02-12T00:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612919#M85139</link>
      <description>&lt;P&gt;&amp;nbsp;You shouldn't take every warning&amp;nbsp;thrown up by security scans to be definite evidence of a problem.&lt;/P&gt;
&lt;P&gt;I suspect that the port used by Plusnet for updating the firmware is being detected. If so then as I understand it this is not a security issue, is present on millions of routers, and will never be closed off.&lt;/P&gt;
&lt;P&gt;Assuming that this is the cause then you can either live with it or buy you own third party router.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 09:50:25 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612919#M85139</guid>
      <dc:creator>Baldrick1</dc:creator>
      <dc:date>2019-02-12T09:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612968#M85140</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/64667"&gt;@pascoej&lt;/a&gt;, your router was upgraded to the latest available build at the start of the month. I don't suppose you can point me in the direction of the scanner you're using?&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/38823"&gt;@Baldrick1&lt;/a&gt;&amp;nbsp;is probably right regarding the open port. It's likely to be TCP port 4567 that is used by the Plusnet Hub One for remote TR069 management/configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 13:59:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612968#M85140</guid>
      <dc:creator>bobpullen</dc:creator>
      <dc:date>2019-02-12T13:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612989#M85141</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I used a Trend Micro scanner and nmap, nmap confirms what the Trend Micro scanner sees. Is there anything I can do about the SSLv2 Drown and SSL Poodle vulnerabilities on the router? Or do I have to buy my own router so i can block these ports?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 15:06:54 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1612989#M85141</guid>
      <dc:creator>pascoej</dc:creator>
      <dc:date>2019-02-12T15:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Router Vulnerabilities Found</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1613020#M85142</link>
      <description>&lt;P&gt;The issue is that the router is using SSLv2 or SSLv3 encryption, both of which are obsolete and vulnerable to attack.&lt;/P&gt;
&lt;P&gt;The router firmware needs to be updated to use TLS (ideally v1.3) for encrypting HTTPS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If there is also a problem with the TR-069 port being open, then it shouldn't be, as the TR-069 protocol is initiated by the device to be configured (i.e. the router) and therefore there is no need for the WAN facing port to be open, as the TR-069 server shouldn't be remotely accessing the router unsolicited.&lt;/P&gt;
&lt;P&gt;Even if the port did have to be open, then it should be restricted to only respond to packets from the FQDN of the Plusnet TR-069 server, and should be invisible to probes from any other source.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/64667"&gt;@pascoej&lt;/a&gt; - what ports is nmap reporting as being open ?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 16:56:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Router-Vulnerabilities-Found/m-p/1613020#M85142</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-02-12T16:56:16Z</dc:date>
    </item>
  </channel>
</rss>

