PT-2016-2299 · Fonality · Fonality

Charlie Wolf

·

Published

2016-06-20

·

Updated

2016-06-21

·

CVE-2016-2362

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fonality versions 12.6 through 14.1i
Description The issue is related to a hardcoded password for the FTP account in the Fonality software, allowing remote attackers to gain access via FTP or SSH connections. This can enable unauthorized access to protected information.
Recommendations For versions 12.6 through 14.1i, update the software to a version released after 2016-06-01 to remove the hardcoded password. As a temporary workaround, consider changing the FTP account password to a unique and secure value until a patched version is available. Restrict access to FTP and SSH connections to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01688
CVE-2016-2362

Affected Products

Fonality