Overview
Fonality (previously trixbox Pro) version 12.6 and later uses a hard-coded password, and the accompanying HUDweb plugin embeds a private SSL key.
Description
CWE-259: Use of Hard-coded Password - CVE-2016-2362 According to the reporter, FTP is used to sync phone configurations for users, by use of a hard-coded username and password. The default SSH server configuration allows the FTP user to also log in via SSH and obtain a shell as the 'nobody' user. |
Impact
A remote attacker with knowledge of the password may be able to log into the server as 'nobody' and execute commands as root. An attacker with knowledge of the private key may be able to conduct impersonation, man-in-the-middle, or passive decryption attacks. |
Solution
Apply an update |
Restrict Network Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9 | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Temporal | 7.7 | E:POC/RL:U/RC:UR |
Environmental | 5.8 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Charlie Wolf for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2016-2362, CVE-2016-2363, CVE-2016-2364 |
Date Public: | 2016-06-01 |
Date First Published: | 2016-06-01 |
Date Last Updated: | 2016-12-21 17:10 UTC |
Document Revision: | 59 |