PT-2007-1988 · Centrality Communications · Pa168
Adrian Pastor
+1
·
Publicado
2007-01-26
·
Atualizado
2018-10-16
·
CVE-2007-0528
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Centrality Communications (aka Aredfox) PA168 chipset and firmware versions 1.54 and earlier
Description
The issue concerns the admin web console, which does not require passwords or authentication tokens when using HTTP. This allows remote attackers to connect to existing superuser sessions, potentially obtaining sensitive information such as passwords and configuration data.
Recommendations
For firmware versions 1.54 and earlier, consider disabling HTTP access to the admin web console until a patch is available. Restrict access to the admin web console to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pa168