Vulnerabilities > CVE-2007-0528 - Information Disclosure vulnerability in Pa168 Chipset

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
centrality-communications
critical
exploit available

Summary

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

Vulnerable Configurations

Part Description Count
Hardware
Centrality_Communications
1

Exploit-Db

descriptionPA168 Chipset IP Phones Weak Session Management Exploit. CVE-2007-0528. Remote exploit for hardware platform
fileexploits/hardware/remote/3189.sh
idEDB-ID:3189
last seen2016-01-31
modified2007-01-24
platformhardware
port
published2007-01-24
reporterAdrian "pagvac" Pastor
sourcehttps://www.exploit-db.com/download/3189/
titlePA168 Chipset IP Phones Weak Session Management Exploit
typeremote