Cisco ATA-186 Web Administration Authentication Bypass Vulnerability
BID:4712
Info
Cisco ATA-186 Web Administration Authentication Bypass Vulnerability
| Bugtraq ID: | 4712 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0769 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Patrick Michael Kane <[email protected]>. |
| Vulnerable: |
Cisco ATA-186 |
| Not Vulnerable: | |
Discussion
Cisco ATA-186 Web Administration Authentication Bypass Vulnerability
The Cisco ATA-186 Analog Telephone Adapter is a hardware device designed to interface between analog telephones and Voice over IP (VoIP). It includes support for web based configuration.
Under some circumstances, it may be possible to bypass the authentication required for this web interface. This may be done with a specially formatted change password request. Exploitation allows a remote attacker to reconfigure the vulnerable device.
The Cisco ATA-186 Analog Telephone Adapter is a hardware device designed to interface between analog telephones and Voice over IP (VoIP). It includes support for web based configuration.
Under some circumstances, it may be possible to bypass the authentication required for this web interface. This may be done with a specially formatted change password request. Exploitation allows a remote attacker to reconfigure the vulnerable device.
Exploit / POC
Cisco ATA-186 Web Administration Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Cisco ATA-186 Web Administration Authentication Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Cisco ATA-186 Web Administration Authentication Bypass Vulnerability
References:
References:
- ATA 186 Homepage (Cisco Systems)