The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2002-07-15T04:00:00

Updated: 2005-06-10T00:00:00

Reserved: 2002-07-09T00:00:00


Link: CVE-2002-0670

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2002-07-23T04:00:00.000

Modified: 2008-09-05T20:28:38.227


Link: CVE-2002-0670

JSON object: View

cve-icon Redhat Information

No data.