Avaya Secure Access Link (SAL) Gateway Invalid Domian Servers Information Disclosure Vulnerability
BID:48942
Info
Avaya Secure Access Link (SAL) Gateway Invalid Domian Servers Information Disclosure Vulnerability
| Bugtraq ID: | 48942 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2011 12:00AM |
| Updated: | Jul 29 2011 12:00AM |
| Credit: | Anonymous. |
| Vulnerable: |
Avaya Secure Access Link 2.0 Avaya Secure Access Link 1.8 Avaya Secure Access Link 1.5 |
| Not Vulnerable: | |
Discussion
Avaya Secure Access Link (SAL) Gateway Invalid Domian Servers Information Disclosure Vulnerability
Avaya Secure Access Link (SAL) gateway is prone to an information-disclosure vulnerability.
To exploit this issue, attackers need to host malicious email servers with 'secavaya.com' and 'secaxeda.com' domain names.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects Secure Access Link 1.5, 1.8, and 2.0.
Avaya Secure Access Link (SAL) gateway is prone to an information-disclosure vulnerability.
To exploit this issue, attackers need to host malicious email servers with 'secavaya.com' and 'secaxeda.com' domain names.
Exploiting this issue may allow an attacker to access sensitive information that may aid in further attacks.
This issue affects Secure Access Link 1.5, 1.8, and 2.0.
Exploit / POC
Avaya Secure Access Link (SAL) Gateway Invalid Domian Servers Information Disclosure Vulnerability
An attacker can exploit this issue by controlling the 'secavaya.com' and 'secaxeda.com' domains.
An attacker can exploit this issue by controlling the 'secavaya.com' and 'secaxeda.com' domains.
Solution / Fix
Avaya Secure Access Link (SAL) Gateway Invalid Domian Servers Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Avaya Secure Access Link (SAL) Gateway Invalid Domian Servers Information Disclosure Vulnerability
References:
References: