vendor:
AdTran Personal Phone Manager
by:
3ndG4me
7.5
CVSS
HIGH
DNS Exfiltration
200
CWE
Product Name: AdTran Personal Phone Manager
Affected Version From: v10.8.1
Affected Version To: v10.8.1
Patch Exists: NO
Related CWE: CVE-2021-25681
CPE: a:adtran:personal_phone_manager
Other Scripts:
N/A
Platforms Tested: NetVanta 7060 and NetVanta 7100
2021
Adtran Personal Phone Manager 10.8.1 – DNS Exfiltration
The AdTran Personal Phone Manager software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS.
Mitigation:
The server should be reconfigured to not perform arbitrary DNS lookups when the Host/Get requests do not match. Additionally scoping requests to only be allowed in the cidr range of the local network should be considered.