vendor:
IP Office Phone Manager
by:
pagvac (Adrian Pastor)
5.5
CVSS
MEDIUM
Cleartext Sensitive Data Vulnerability
798
CWE
Product Name: IP Office Phone Manager
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2005
Avaya IP Office Phone Manager – Cleartext Sensitive Data Vulnerability Exploit v0.01
This exploit allows an attacker to retrieve sensitive data, such as usernames, IP addresses, and passwords, from Avaya IP Office Phone Manager. It works by querying the Windows registry for specific values and printing them to the console.
Mitigation:
The vendor should encrypt sensitive data stored in the Windows registry to prevent unauthorized access. Users should also ensure that only trusted individuals have access to the registry.