Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to cause a continual denial-of-service condition.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/107031 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-19-045-01 | third party advisory us government resource |