cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
972
Views
5
Helpful
6
Replies

UCCE Rogger Vulnerability - port 69 open

anthonyroesler
Level 1
Level 1

We have been given a scan of our rogger that is showing open on port 69 UDP and accepting connections. Trying to determine why that could be and what we need to do to shut it down. This is open on our A side, but not on our B side.

 

Version 11.6.2

1 Accepted Solution

Accepted Solutions

Perhaps someone installed software for TFTP to do things like transfer files to voice gateways and never removed it?

View solution in original post

6 Replies 6

Omar Deen
Spotlight
Spotlight

Port 69 UDP is TFTP... and since this is only happening on Side A, I'm going to guess that you're running the Outbound Dialer and are using TFTP to bring in a dialing list for your campaigns.

Incorrect, we do not use dialer at all.

Regardless, TFTP is using that port

Perhaps someone installed software for TFTP to do things like transfer files to voice gateways and never removed it?

This was it. Someone did install a TFTP client. It's been removed now! Thanks!

Good deal, glad that it resolved it and thanks for posting the confirmation.

 

And you probably know this, but if you had an issue with that server, and Cisco saw that you had that third party software on there, they may tell you that you have to remove it before they would continue to troubleshoot it. Here's an article about it.

https://www.cisco.com/c/en/us/products/collateral/customer-collaboration/unified-ip-interactive-voice-response-ivr/prod_bulletin09186a0080207fb9.html