CVE-2018-11518
Summary
| CVE | CVE-2018-11518 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-30 20:29:00 UTC |
| Updated | 2018-07-20 16:10:00 UTC |
| Description | A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone call, an attacker can record these frequencies and use them for service activations. This is a request-forgery issue when the required series of DTMF signals for a service activation is predictable (e.g., the IVR system does not speak a nonce to the caller). In this case, the IVR system accepts an activation request from a less-secure channel (any loudspeaker in the caller's physical environment) without verifying that the request was intended (it matches a nonce sent over a more-secure channel to the caller's earpiece). |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hcltech | Legacy Ivr | - | All | All | All |
| Hardware | Hcltech | Legacy Ivr | - | All | All | All |
| Operating System | Hcltech | Legacy Ivr Firmware | - | All | All | All |
| Operating System | Hcltech | Legacy Ivr Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Dhiraj 的 Twitter: “The IVR nowadays includes multiple functionalities like recharges and subscriptions for services which can also be done even with modern Telecom operators. #DiggingOldSys… https://t.co/QBdbZUiEli” | MISC | twitter.com | Third Party Advisory |
| A Virgil's Guide to Pentest: 0day - Legacy IVR - Let's Phreak | MISC | virgil-cj.blogspot.com | Third Party Advisory |
| Abusing IVR Systems - Legacy Telecom [CVE-2018-11518] ~ inputzero | MISC | datarift.blogspot.com | Third Party Advisory |
| Dhiraj op Twitter: "Yes there is no boundry crossing here and it does follow the flow but the flow is controlled by someone else not the user who has initiated the call. Select 1 for English is just an example to show we can control other users flow without their consent. 1/n… https://t.co/rTME60EolO" | MISC | twitter.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.