vendor:
Blue Angel Software Suite
by:
Paolo Serracino
6.5
CVSS
MEDIUM
Authenticated Command Execution
78
CWE
Product Name: Blue Angel Software Suite
Affected Version From: All
Affected Version To: All
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Embedded Linux OS
2019
Blue Angel Software Suite – Authenticated Command Execution
Blue Angel Software Suite, an application that runs on embedded devices for VOIP/SIP services is vulnerable to an authenticated command execution in ping command. All default accounts can be used to login and achieve command execution, including the guest one. Moreover there's another account, defined in the local file device.dat, that provides an apparently 'backdoor' account.
Mitigation:
Ensure that all default accounts are disabled and that the 'backdoor' account is removed from the local file device.dat.