Vulnerabilities > CVE-2014-2560 - Use of Password Hash With Insufficient Computational Effort vulnerability in Phoner Phonerlite
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | PhonerLite 2.14 SIP Soft Phone - SIP Digest Disclosure. CVE-2014-2560. Remote exploit for windows platform |
id | EDB-ID:32643 |
last seen | 2016-02-03 |
modified | 2014-04-01 |
published | 2014-04-01 |
reporter | Jason Ostrom |
source | https://www.exploit-db.com/download/32643/ |
title | PhonerLite 2.14 SIP Soft Phone - SIP Digest Disclosure |
Packetstorm
data source | https://packetstormsecurity.com/files/download/125965/phonerlite-disclose.txt |
id | PACKETSTORM:125965 |
last seen | 2016-12-05 |
published | 2014-03-31 |
reporter | Jason Ostrom |
source | https://packetstormsecurity.com/files/125965/PhonerLite-2.14-Digest-Information-Leak.html |
title | PhonerLite 2.14 Digest Information Leak |
Seebug
bulletinFamily exploit description Bugtraq ID:66539 CVE ID:CVE-2014-2560 PhonerLite是一款网络电话应用,可以让您的电脑使用新的互联网电话技术电话(VoIP,IP语音)。 PhonerLite允许恶意第三方伪造SIP INVITE消息,获取目标用户的SIP MD5摘要验证用户验证凭据哈希值。 0 PhonerLite 2.14 PhonerLite 2.15版本已修复该漏洞,建议用户下载使用: http://www.ektron.com/ id SSV:62015 last seen 2017-11-19 modified 2014-04-01 published 2014-04-01 reporter Root title PhonerLite SIP摘要远程信息泄漏漏洞 bulletinFamily exploit description No description provided by source. id SSV:85923 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-85923 title PhonerLite 2.14 SIP Soft Phone - SIP Digest Disclosure