Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/34887 | vdb entry |
http://www.ingate.com/relnote-452.php | |
http://secunia.com/advisories/25420 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2007/1973 | vdb entry |
http://osvdb.org/36708 | vdb entry |