HIGH · 9.0

CVE-2007-0528

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentica...

Vulnerability Description

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Centrality CommunicationsPa168 Chipset<= firmware_1.54

References

FAQ

What is CVE-2007-0528?

CVE-2007-0528 is a vulnerability with a CVSS score of 9.0 (HIGH). The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentica...

How severe is CVE-2007-0528?

CVE-2007-0528 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0528?

Check the references section above for vendor advisories and patch information. Affected products include: Centrality Communications Pa168 Chipset.