J-Security Center

Title: Pingtel Expressa Default Blank Administrator Password Vulnerability

Severity: CRITICAL

Description:

Expressa is the Java-Based Voice-Over-IP phone developed and distributed by Pingtel.

A problem with Expressa phones could make it possible for a user to gain administrative access to a vulnerable phone.

It has been discovered that Pingtel Expressa phones do not require the setting of an administrator password by default. The default password set for Expressa phones is a NULL value, which allows access to administrative functions without authentication whatsoever. A phone without the administrative password set could be accessed remotely by an attacker via the web interface.

This problem could allow a user with either local, physical access, or access to the phone across a network medium to gain administrative access to the vulnerable device.

Affected Products:

  • Pingtel Xpressa 1.2.5
  • Pingtel Xpressa 1.2.7 .4

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.