PT-2002-1699 · Pingtel · Pingtel Xpressa

Publicado

2002-07-23

·

Atualizado

2008-09-05

·

CVE-2002-0673

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pingtel xpressa SIP-based voice-over-IP phone versions 1.2.5 through 1.2.7.4
Description The issue concerns the enrollment process, which allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In. This enables them to gain remote access and perform unauthorized actions.
Recommendations For versions 1.2.5 through 1.2.7.4, consider restricting physical access to the phone to prevent unauthorized re-registration. As a temporary workaround, restrict the use of MyPingtel Sign-In on affected phones until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0673

Produtos afetados

Pingtel Xpressa