Polycom ViewStation Plain Text Administrative Password Vulnerability
BID:6447
Info
Polycom ViewStation Plain Text Administrative Password Vulnerability
| Bugtraq ID: | 6447 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2002 12:00AM |
| Updated: | Dec 20 2002 12:00AM |
| Credit: | Discovery is credited to Tamer Sahin. |
| Vulnerable: |
Polycom ViewStation FX/VS 4000 4.2 |
| Not Vulnerable: | |
Discussion
Polycom ViewStation Plain Text Administrative Password Vulnerability
Polycom ViewStation stores the administrator and software update account passwords in plain text within a HTML file. This file can be accessed through the URI http://<target>/a_security.htm.
Polycom ViewStation stores the administrator and software update account passwords in plain text within a HTML file. This file can be accessed through the URI http://<target>/a_security.htm.
Exploit / POC
Polycom ViewStation Plain Text Administrative Password Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Polycom ViewStation Plain Text Administrative Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Polycom ViewStation Plain Text Administrative Password Vulnerability
References:
References:
- Home Page (Polycom)
- Polycom Video Conference System Management Server Authentication Bypass Vulnerab (SecurityOffice)