vendor:
Phones
by:
Daniel Svartman
8,8
CVSS
HIGH
Unauthorized Access
284
CWE
Product Name: Phones
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Proof of Concept on how to get tftp config files from cisco phones
This exploit allows an attacker to anonymously download configuration files from Cisco phones. The attacker can then use the information gathered from the files to gain access to personal information and credentials from LDAP. The exploit is performed by using the first 8 digits of the MAC address and the last 4 digits are generated automatically. The attacker then downloads the files using the TFTP server and processes the SPDefault.cnf.xml file to gain access to the LDAP IP address, user ID, password, and base DN.
Mitigation:
Ensure that all Cisco phones are configured with strong passwords and that access to the TFTP server is restricted to authorized personnel only.