Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-0528

Опубликовано: 26 янв. 2007
Источник: nvd
CVSS2: 9
EPSS Средний

Описание

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:h:centrality_communications:pa168_chipset:*:*:*:*:*:*:*:*
Версия до firmware_1.54 (включая)

EPSS

Процентиль: 94%
0.15008
Средний

9 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

EPSS

Процентиль: 94%
0.15008
Средний

9 Critical

CVSS2

Дефекты

NVD-CWE-Other