PT-2016-2299 · Fonality · Fonality

Charlie Wolf

·

Publicado

2016-06-20

·

Atualizado

2016-06-21

·

CVE-2016-2362

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fonality versions 12.6 through 14.1i
Description The issue is related to a hardcoded password for the FTP account in the Fonality software, allowing remote attackers to gain access via FTP or SSH connections. This can enable unauthorized access to protected information.
Recommendations For versions 12.6 through 14.1i, update the software to a version released after 2016-06-01 to remove the hardcoded password. As a temporary workaround, consider changing the FTP account password to a unique and secure value until a patched version is available. Restrict access to FTP and SSH connections to minimize the risk of exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01688
CVE-2016-2362

Produtos afetados

Fonality