Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco VoIP Phone Web Interface System Memory Contents Information Leakage Vulnerability

The 7900 series VoIP Phones are a Voice-Over-IP solution distributed by Cisco Systems.

By placing a request to the /PortInformation script with a port ID (i.e. http://www.example.com/PortInformation?<port> where <port> is an integer value) of arbitrarily high value, the web server will return a dump of the contents of phone memory. This has been reportedly reproduced by passing port ID values of greater than 32768, and consistently reproduced with a value of 120000.







 

Privacy Statement
Copyright 2008, SecurityFocus