Clipcomm CPW-100E and CP-100E VOIP Phones Remote Administrative Access Vulnerability
BID:16289
Info
Clipcomm CPW-100E and CP-100E VOIP Phones Remote Administrative Access Vulnerability
| Bugtraq ID: | 16289 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2006 12:00AM |
| Updated: | Jan 17 2006 12:00AM |
| Credit: | Discovered by Shawn Merdinger <[email protected]>. |
| Vulnerable: |
Clipcomm CPW-100E VOIP WIFI Phone 1.1.12 Clipcomm CP-100E VOIP WIFI Phone 1.1.60 |
| Not Vulnerable: | |
Discussion
Clipcomm CPW-100E and CP-100E VOIP Phones Remote Administrative Access Vulnerability
Clipcomm CPW-100E and CP-100E VOIP phones allow unauthenticated, remote administrative access.
This issue allows remote attackers to gain access to potentially sensitive information, trace calls, perform factory resets, and corrupt memory; other attacks are also possible. Attackers may also turn CPW-100E phones into a remote listening device.
Clipcomm CPW-100E phones running firmware version 1.1.12, and CP-100E phones running firmware version 1.1.60 are prone to this issue. Due to code reuse, other devices and versions may also be affected.
Clipcomm CPW-100E and CP-100E VOIP phones allow unauthenticated, remote administrative access.
This issue allows remote attackers to gain access to potentially sensitive information, trace calls, perform factory resets, and corrupt memory; other attacks are also possible. Attackers may also turn CPW-100E phones into a remote listening device.
Clipcomm CPW-100E phones running firmware version 1.1.12, and CP-100E phones running firmware version 1.1.60 are prone to this issue. Due to code reuse, other devices and versions may also be affected.
Exploit / POC
Clipcomm CPW-100E and CP-100E VOIP Phones Remote Administrative Access Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Clipcomm CPW-100E and CP-100E VOIP Phones Remote Administrative Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Clipcomm CPW-100E and CP-100E VOIP Phones Remote Administrative Access Vulnerability
References:
References:
- Clipcomm VOIP Phone Product Page (Clipcomm)