PT-2006-1446 · Advantage Century Telecommunication · Act P202S Ip Phone
Published
2006-01-22
·
Updated
2017-07-20
·
CVE-2006-0375
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Advantage Century Telecommunication (ACT) P202S IP Phone version 1.01.21
Description
The issue concerns the use of a hardcoded Network Time Protocol (NTP) server, which could allow remote attackers to manipulate time information. This could lead to providing false time information, blocking access to time information, or conducting other attacks.
Recommendations
For version 1.01.21, consider configuring an alternative NTP server to mitigate the risk of relying on a hardcoded server. As a temporary workaround, restrict access to the NTP service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Act P202S Ip Phone