PT-2015-7504 · Csl · Csl Dualcom Gprs Cs2300-R

Andrew Tierney

·

Published

2015-11-25

·

Updated

2015-11-27

·

CVE-2015-7286

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53
Description The issue concerns the use of a polyalphabetic substitution cipher with hardcoded keys in the affected devices. This makes it easier for remote attackers to defeat the cryptographic protection mechanism by capturing IP or V.22bis PSTN protocol traffic.
Recommendations For CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53, consider updating the firmware to a version that does not rely on hardcoded keys for cryptographic protection, if such an update is available. As a temporary workaround, restrict access to the device's network traffic to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7286

Affected Products

Csl Dualcom Gprs Cs2300-R