OmniPCX Enterprise Audio Rerouting Information Disclosure And Denial Of Service Vulnerability
BID:26494
Info
OmniPCX Enterprise Audio Rerouting Information Disclosure And Denial Of Service Vulnerability
| Bugtraq ID: | 26494 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-5361 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2007 12:00AM |
| Updated: | Nov 20 2007 04:14PM |
| Credit: | Daniel Stirnimann is credited with the discovery of this issue. |
| Vulnerable: |
Alcatel-Lucent OmniPCX Enterprise 7.1 Alcatel-Lucent OmniPCX Enterprise 7 Alcatel-Lucent OmniPCX Enterprise 6.2 Alcatel-Lucent OmniPCX Enterprise 6.1 Alcatel-Lucent OmniPCX Enterprise 6.0 |
| Not Vulnerable: | |
Discussion
OmniPCX Enterprise Audio Rerouting Information Disclosure And Denial Of Service Vulnerability
OmniPCX Enterprise is prone to an information-disclosure and denial-of-service vulnerability; fixes are available.
Attackers can exploit this issue to cause an IP Touch telephone to route incoming audio to an attacker-controlled source.
Users will be denied access to incoming audio on placed or received calls on the phone. Attackers could obtain potentially sensitive information while listening to the routed audio.
OmniPCX Enterprise 7.1 and prior versions are vulnerable.
OmniPCX Enterprise is prone to an information-disclosure and denial-of-service vulnerability; fixes are available.
Attackers can exploit this issue to cause an IP Touch telephone to route incoming audio to an attacker-controlled source.
Users will be denied access to incoming audio on placed or received calls on the phone. Attackers could obtain potentially sensitive information while listening to the routed audio.
OmniPCX Enterprise 7.1 and prior versions are vulnerable.
Exploit / POC
OmniPCX Enterprise Audio Rerouting Information Disclosure And Denial Of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
OmniPCX Enterprise Audio Rerouting Information Disclosure And Denial Of Service Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor released an advisory and fixes to address this issue. Please see the referenced advisory for more information.
References
OmniPCX Enterprise Audio Rerouting Information Disclosure And Denial Of Service Vulnerability
References:
References:
- Vendor Homepage (Alcatel-Lucent)
- IP Touch Denial of Service through crafted TFTP request (Alcatel-Lucent)