PT-2022-12320 · Sangoma Technologies · Switchvox
Published
2022-02-14
·
Updated
2022-07-12
·
CVE-2021-45310
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sangoma Technologies Corporation Switchvox version 102409
Description
The issue is related to an information disclosure vulnerability due to improper access restriction. User information, including first name, last name, account id, server uuid, email address, profile image, number, timestamps, etc., can be extracted by sending an unauthenticated HTTP GET request to the "https://Switchvox-IP/main?cmd=invalid browser" endpoint. The
account id, server uuid, email address, and other user details are accessible through this method.Recommendations
For Sangoma Technologies Corporation Switchvox version 102409, as a temporary workaround, consider restricting access to the "https://Switchvox-IP/main?cmd=invalid browser" endpoint until a patch is available. Avoid using this endpoint in unauthenticated requests to minimize the risk of information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Switchvox