PT-2007-1988 · Centrality Communications · Pa168

Adrian Pastor

+1

·

Publicado

2007-01-26

·

Atualizado

2018-10-16

·

CVE-2007-0528

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Centrality Communications (aka Aredfox) PA168 chipset and firmware versions 1.54 and earlier
Description The issue concerns the admin web console, which does not require passwords or authentication tokens when using HTTP. This allows remote attackers to connect to existing superuser sessions, potentially obtaining sensitive information such as passwords and configuration data.
Recommendations For firmware versions 1.54 and earlier, consider disabling HTTP access to the admin web console until a patch is available. Restrict access to the admin web console to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0528

Produtos afetados

Pa168