PT-2002-1699 · Pingtel · Pingtel Xpressa

Published

2002-07-23

·

Updated

2008-09-05

·

CVE-2002-0673

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pingtel xpressa SIP-based voice-over-IP phone versions 1.2.5 through 1.2.7.4
Description The issue concerns the enrollment process, which allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In. This enables them to gain remote access and perform unauthorized actions.
Recommendations For versions 1.2.5 through 1.2.7.4, consider restricting physical access to the phone to prevent unauthorized re-registration. As a temporary workaround, restrict the use of MyPingtel Sign-In on affected phones until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0673

Affected Products

Pingtel Xpressa