PT-2006-4436 · Bt · Bt Voyager 2091 Wireless
Pagvac
·
Published
2006-07-13
·
Updated
2018-10-18
·
CVE-2006-3561
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BT Voyager 2091 Wireless firmware versions 2.21.05.08m A2pB018c1.d16d and earlier
BT Voyager 2091 Wireless firmware versions 3.01m and earlier
Description
The issue allows remote attackers to bypass the authentication process and gain sensitive information. This can include configuration information via the "/btvoyager getconfig.sh" endpoint, PPP credentials via the "btvoyager getpppcreds.sh" endpoint, and decoding configuration credentials via the "btvoyager decoder.c" file.
Recommendations
For BT Voyager 2091 Wireless firmware versions 2.21.05.08m A2pB018c1.d16d and earlier, consider updating to a version later than 2.21.05.08m A2pB018c1.d16d to resolve the issue.
For BT Voyager 2091 Wireless firmware versions 3.01m and earlier, consider updating to a version later than 3.01m to resolve the issue.
As a temporary workaround, consider restricting access to the "/btvoyager getconfig.sh", "btvoyager getpppcreds.sh", and "btvoyager decoder.c" to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bt Voyager 2091 Wireless