Nortel Networks Communication Server 1000 Multiple Security Vulnerabilities
BID:28691
Info
Nortel Networks Communication Server 1000 Multiple Security Vulnerabilities
| Bugtraq ID: | 28691 |
| Class: | Unknown |
| CVE: |
CVE-2008-6564 CVE-2008-6576 CVE-2008-6577 CVE-2008-6578 CVE-2008-6579 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2008 12:00AM |
| Updated: | Apr 15 2009 04:36PM |
| Credit: | VoIPshield |
| Vulnerable: |
Nortel Networks Communications Server 1000 |
| Not Vulnerable: | |
Discussion
Nortel Networks Communication Server 1000 Multiple Security Vulnerabilities
Nortel Networks Communication Server 1000 is prone to multiple security vulnerabilities, including hard-coded authentication credentials, as well as multiple vulnerabilities that can cause denial-of-service conditions, disclose sensitive information, or allow unauthorized access.
Attackers can leverage these issues to bypass authentication mechanisms, prevent endpoints from obtaining configuration files and firmware updates, or obtain sensitive information that may aid in launching further attacks.
Few details are available regarding these issues. We will update this BID as more information becomes available.
Communications Server 1000 with firmware 4.5.x is affected; other versions may also be vulnerable.
Nortel Networks Communication Server 1000 is prone to multiple security vulnerabilities, including hard-coded authentication credentials, as well as multiple vulnerabilities that can cause denial-of-service conditions, disclose sensitive information, or allow unauthorized access.
Attackers can leverage these issues to bypass authentication mechanisms, prevent endpoints from obtaining configuration files and firmware updates, or obtain sensitive information that may aid in launching further attacks.
Few details are available regarding these issues. We will update this BID as more information becomes available.
Communications Server 1000 with firmware 4.5.x is affected; other versions may also be vulnerable.
Exploit / POC
Nortel Networks Communication Server 1000 Multiple Security Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
References
Nortel Networks Communication Server 1000 Multiple Security Vulnerabilities
References:
References:
- Communication Server 1000 Product Page (Nortel Networks)
- CS1000 FTP Session Limit Exhaustion (VoIPshield)
- CS1000 Multiple Hardcoded Passwords (VoIPshield)
- Multiple Command Injection Vulnerabilities (VoIPshield)
- Web Application Structure Disclosure (VoIPshield)
- Nortel response to VoIP potential security vulnerabilities in CS 1000 (Nortel)