Aastra 6753i '.tug' Configuraton File Information Disclosure Vulnerability
BID:57151
Info
Aastra 6753i '.tug' Configuraton File Information Disclosure Vulnerability
| Bugtraq ID: | 57151 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2013 12:00AM |
| Updated: | Jan 03 2013 12:00AM |
| Credit: | Timo Juhani Lindfors |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Anacrypt '.tuz' Configuraton File Information Disclosure Vulnerability
Anacrypt is prone to an information-disclosure vulnerability.
Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
Versions prior to Anacrypt 1.04 are vulnerable.
Note: This issue was previously titled 'Aastra 6753i '.tuz' Configuraton File Information Disclosure Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
Anacrypt is prone to an information-disclosure vulnerability.
Successful exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
Versions prior to Anacrypt 1.04 are vulnerable.
Note: This issue was previously titled 'Aastra 6753i '.tuz' Configuraton File Information Disclosure Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
Exploit / POC
Anacrypt '.tuz' Configuraton File Information Disclosure Vulnerability
Currently, we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Anacrypt '.tuz' Configuraton File Information Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Anacrypt '.tuz' Configuraton File Information Disclosure Vulnerability
References:
References:
- Aastra 6753i IP Phone Configuration Encryption Weakness Information Disclosure (OSVDB)
- Aastra Homepage (Aastra Technologies Limited)
- Aastra IP Telephone encrypted .tuz configuration file leakage (Timo Juhani Lindfors)
- Aastra IP Telephone encrypted .tuz configuration file leakage (Aastra)
- Aastra 6753i Phone Home Page (Aastra)