Search: "pingtel"

12 CVEs found

CVE-2002-0667
10.0 HIGH

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.

Published: 2002-07-23
Products: 2
Vendors:
pingtel

The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls.

Published: 2002-07-23
Products: 2
Vendors:
pingtel

The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to st...

Published: 2002-07-23
Products: 2
Vendors:
pingtel
CVE-2002-0671
9.8 CRITICAL

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attacker...

Published: 2002-07-23
Products: 3
Vendors:
pingtel
CVE-2002-0672
4.6 MEDIUM

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets ...

Published: 2002-07-23
Products: 2
Vendors:
pingtel
CVE-2002-0673
4.6 MEDIUM

The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone ...

Published: 2002-07-23
Products: 2
Vendors:
pingtel

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the adminis...

Published: 2002-07-23
Products: 2
Vendors:
pingtel
CVE-2002-0675
4.6 MEDIUM

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone.

Published: 2002-07-23
Products: 2
Vendors:
pingtel
CVE-2002-1934
5.0 MEDIUM

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the physi...

Published: 2002-12-31
Products: 5
Vendors:
pingtel
CVE-2002-1935
5.0 MEDIUM

Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to ...

Published: 2002-12-31
Products: 5
Vendors:
pingtel
CVE-2002-0669
5.0 MEDIUM

The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force aut...

Published: 2003-02-19
Products: 2
Vendors:
pingtel
CVE-2004-1680
5.0 MEDIUM

application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly trigge...

Published: 2004-09-13
Products: 6
Vendors:
pingtel