vendor:
VoIP phones
by:
Adrian Pastor
5.5
CVSS
MEDIUM
Session-hijacking
613
CWE
Product Name: VoIP phones
Affected Version From: SIP Firmware V1.42
Affected Version To: SIP Firmware 1.54
Patch Exists: NO
Related CWE: Not assigned
CPE: h:aredfox:pa168_chipset
Platforms Tested:
2007
Session-hijacking vulnerability in VoIP phones using Aredfox PA168 Chipset
An attacker can exploit this issue to gain administrative access to the embedded webserver running on the affected device. This may allow attackers to completely compromise affected devices.
Mitigation:
Unknown