snom VoIP Phone Firmware Web Interface Remote Security Bypass Vulnerability
BID:40771
Info
snom VoIP Phone Firmware Web Interface Remote Security Bypass Vulnerability
| Bugtraq ID: | 40771 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-2291 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | snom |
| Vulnerable: |
snom technology VoIP phone firmware 8.2.34 snom technology VoIP phone firmware 8.2.33 snom technology VoIP phone firmware 8.2.32 snom technology VoIP phone firmware 8.2.31 snom technology VoIP phone firmware 8.2.30 |
| Not Vulnerable: |
snom technology VoIP phone firmware 8.2.35 |
Discussion
snom VoIP Phone Firmware Web Interface Remote Security Bypass Vulnerability
snom VoIP phone firmware web interface is prone to a security-bypass vulnerability because the application fails to properly perform access checks.
Attackers can exploit this issue to bypass certain security restrictions and edit user credentials.
snom VoIP phone firmware versions prior to 8.2.35 are vulnerable.
snom VoIP phone firmware web interface is prone to a security-bypass vulnerability because the application fails to properly perform access checks.
Attackers can exploit this issue to bypass certain security restrictions and edit user credentials.
snom VoIP phone firmware versions prior to 8.2.35 are vulnerable.
Exploit / POC
snom VoIP Phone Firmware Web Interface Remote Security Bypass Vulnerability
Attackers can exploit this issue with a client application such as a browser.
Attackers can exploit this issue with a client application such as a browser.
Solution / Fix
snom VoIP Phone Firmware Web Interface Remote Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
snom VoIP Phone Firmware Web Interface Remote Security Bypass Vulnerability
References:
References: