Vulnerabilities > CVE-2007-0528 - Unspecified vulnerability in Centrality Communications Pa168 Chipset

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
centrality-communications
exploit available

Summary

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

Vulnerable Configurations

Part Description Count
Hardware
Centrality_Communications
1

Exploit-Db

descriptionPA168 Chipset IP Phones Weak Session Management Exploit. CVE-2007-0528. Remote exploit for hardware platform
fileexploits/hardware/remote/3189.sh
idEDB-ID:3189
last seen2016-01-31
modified2007-01-24
platformhardware
port
published2007-01-24
reporterAdrian "pagvac" Pastor
sourcehttps://www.exploit-db.com/download/3189/
titlePA168 Chipset IP Phones Weak Session Management Exploit
typeremote