PT-2015-7504 · Csl · Csl Dualcom Gprs Cs2300-R

Andrew Tierney

·

Publicado

2015-11-25

·

Atualizado

2015-11-27

·

CVE-2015-7286

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53
Description The issue concerns the use of a polyalphabetic substitution cipher with hardcoded keys in the affected devices. This makes it easier for remote attackers to defeat the cryptographic protection mechanism by capturing IP or V.22bis PSTN protocol traffic.
Recommendations For CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53, consider updating the firmware to a version that does not rely on hardcoded keys for cryptographic protection, if such an update is available. As a temporary workaround, restrict access to the device's network traffic to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7286

Produtos afetados

Csl Dualcom Gprs Cs2300-R