snom VoIP Phone Web Interface HTTP Request Authentication Bypass Vulnerability
BID:43130
Info
snom VoIP Phone Web Interface HTTP Request Authentication Bypass Vulnerability
| Bugtraq ID: | 43130 |
| Class: | Design Error |
| CVE: |
CVE-2009-1048 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2009 12:00AM |
| Updated: | Aug 13 2009 12:00AM |
| Credit: | Walter Sprenger of Compass Security AG |
| Vulnerable: |
snom technology Snom820 7.1.35 snom technology Snom820 7.1.30 snom technology Snom820 6.5.18 snom technology Snom820 6.5.17 snom technology Snom 320 SIP Phone 3.2.5 linux |
| Not Vulnerable: |
snom technology Snom820 7.3.14 snom technology Snom820 7.1.39 snom technology Snom820 6.5.20 |
Discussion
snom VoIP Phone Web Interface HTTP Request Authentication Bypass Vulnerability
The web interface on snom VoIP phones is prone to an authentication-bypass vulnerability because it fails to properly verify HTTP requests.
Successful exploits may allow attackers to bypass security restrictions and reconfigure the phones or make arbitrary use of the phones.
snom VoIP phones with firmware prior to 6.5.20, 7.1.39 and 7.3.14 are vulnerable.
The web interface on snom VoIP phones is prone to an authentication-bypass vulnerability because it fails to properly verify HTTP requests.
Successful exploits may allow attackers to bypass security restrictions and reconfigure the phones or make arbitrary use of the phones.
snom VoIP phones with firmware prior to 6.5.20, 7.1.39 and 7.3.14 are vulnerable.
References
snom VoIP Phone Web Interface HTTP Request Authentication Bypass Vulnerability
References:
References:
- snom technology Homepage (snom technology AG)
- Authentication Bypass of Snom Phone Web Interface (Walter Sprenger)