PT-2016-2299 · Fonality · Fonality
Charlie Wolf
·
Published
2016-06-20
·
Updated
2016-06-21
·
CVE-2016-2362
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fonality versions 12.6 through 14.1i
Description
The issue is related to a hardcoded password for the FTP account in the Fonality software, allowing remote attackers to gain access via FTP or SSH connections. This can enable unauthorized access to protected information.
Recommendations
For versions 12.6 through 14.1i, update the software to a version released after 2016-06-01 to remove the hardcoded password. As a temporary workaround, consider changing the FTP account password to a unique and secure value until a patched version is available. Restrict access to FTP and SSH connections to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fonality