vendor:
by:
Adrian Pastor
5.5
CVSS
MEDIUM
weak session management vulnerability
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: Not assigned
CPE:
Platforms Tested:
2007
PR06-14: IP Phones based on Centrality Communications/Aredfox PA168 chipset weak session management vulnerability
There is a problem with the way IP Phones using the PA168 chipset handle authenticated sessions, allowing remote attackers to gain access to the admin web console running as superuser.
Mitigation:
Not provided