PT-2007-1988 · Centrality Communications · Pa168
Adrian Pastor
+1
·
Published
2007-01-26
·
Updated
2018-10-16
·
CVE-2007-0528
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Centrality Communications (aka Aredfox) PA168 chipset and firmware versions 1.54 and earlier
Description
The issue concerns the admin web console, which does not require passwords or authentication tokens when using HTTP. This allows remote attackers to connect to existing superuser sessions, potentially obtaining sensitive information such as passwords and configuration data.
Recommendations
For firmware versions 1.54 and earlier, consider disabling HTTP access to the admin web console until a patch is available. Restrict access to the admin web console to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pa168