Quintum”s Service Tech sent out the following urgent message on January 14, 2004:
“As we explained 2 days ago, we have seen and heard from many customers where their Tenors are resetting many times for no reason. We had reported at that time that this seems to be some sort of Internet Attack/Worm. Originally we had thought that the attack was coming to the Tenors as an ICMP message. Since then and in further investigation, we find that the attack is actually taking place through the well known H.323 port of 1720. This seems to be a fragmented H.225 message coming in to the Tenor from IP. This vulnerability will affect all VoIP Gateway manufacturers. In the case of the Tenor, it is resetting due to this attack and the number of messages coming in to it.”