Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://www.digigram.com/download/pyko-out-user-manual-en-jan-2019/ | product |
https://www.kb.cert.org/vuls/id/360686 | third party advisory |