PT-2014-3209 · Enghouse Interactive+1 · Enghouse Interactive Ivr Pro+1
Published
2014-01-28
·
Updated
2014-01-31
·
CVE-2013-6838
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Enghouse Interactive IVR Pro (VIP2000) version 9.0.3
Description
The issue concerns an unspecified "addon product" in Enghouse Interactive IVR Pro, where the same SSH private key is used across different customers' installations when OpenVZ and fallback customization are utilized. This allows remote attackers to gain privileges by leveraging knowledge of this key.
Recommendations
For Enghouse Interactive IVR Pro (VIP2000) version 9.0.3, consider regenerating and using unique SSH private keys for each customer's installation to prevent unauthorized access. As a temporary workaround, restrict access to the SSH service until a more permanent solution can be implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enghouse Interactive Ivr Pro
Openvz