PT-2002-1699 · Pingtel · Pingtel Xpressa
Published
2002-07-23
·
Updated
2008-09-05
·
CVE-2002-0673
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pingtel xpressa SIP-based voice-over-IP phone versions 1.2.5 through 1.2.7.4
Description
The issue concerns the enrollment process, which allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In. This enables them to gain remote access and perform unauthorized actions.
Recommendations
For versions 1.2.5 through 1.2.7.4, consider restricting physical access to the phone to prevent unauthorized re-registration. As a temporary workaround, restrict the use of MyPingtel Sign-In on affected phones until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pingtel Xpressa