PT-2015-7504 · Csl · Csl Dualcom Gprs Cs2300-R
Andrew Tierney
·
Publicado
2015-11-25
·
Atualizado
2015-11-27
·
CVE-2015-7286
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53
Description
The issue concerns the use of a polyalphabetic substitution cipher with hardcoded keys in the affected devices. This makes it easier for remote attackers to defeat the cryptographic protection mechanism by capturing IP or V.22bis PSTN protocol traffic.
Recommendations
For CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53, consider updating the firmware to a version that does not rely on hardcoded keys for cryptographic protection, if such an update is available. As a temporary workaround, restrict access to the device's network traffic to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Csl Dualcom Gprs Cs2300-R