9
CVSSv2

CVE-2007-0528

Published: 26/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and previous versions, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote malicious users to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

Vulnerable Product Search on Vulmon Subscribe to Product

centrality communications pa168 chipset

Exploits

#!/bin/bash # PR06-14: IP Phones based on Centrality Communications/Aredfox PA168 chipset weak session management vulnerability # Author: Adrian Pastor [adrianpastor-AT-procheckupcom] from ProCheckUp # This advisory has been published following consultation with UK NISCC [wwwnisccgovuk/] # Date Found: 3rd November 2006 # Date Public: ...