The default configuration of the HTTP server in Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not require authentication for sensitive configuration pages, which allows remote attackers to modify configuration.
Link | Tags |
---|---|
http://secunia.com/advisories/17628 | third party advisory patch vendor advisory |
http://www.hitachi-cable.co.jp/ICSFiles/infosystem/security/76659792_e.pdf | |
http://marc.info/?l=full-disclosure&m=113217425618951&w=2 | mailing list |