what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Nortel Application Gateway 2000 Password

Nortel Application Gateway 2000 Password
Posted Apr 15, 2009
Authored by D. Matscheko | Site sec-consult.com

SEC Consult Security Advisory 20090415-1 - The Nortel Application Gateway 2000 versions 6.3.1 and below suffer from a password disclosure vulnerability.

tags | exploit
SHA-256 | 6a602258e8f29deb14f3eb5ff281f26e0e43c3f7484aceaeafab1860a788f32d

Nortel Application Gateway 2000 Password

Change Mirror Download
SEC Consult Security Advisory < 20090415-1 >
==========================================================================
title: Nortel Application Gateway 2000 Password
Disclosure Vulnerability
program: Nortel Application Gateway 2000
vulnerable version: 6.3.1 and prior
homepage: http://www.nortel.com/ag2000
found: 2008-11-14
by: David Matscheko / SEC Consult / www.sec-consult.com
link:
https://www.sec-consult.com/files/20090415-1_nortel_AG_password_disclosure.txt
==========================================================================

Vendor description:
-------------------

The Application Gateway delivers practical, converged voice and data
applications on Nortel IP phones that enable organizations to benefit
more fully from IP telephony. The prepackaged, easy-to-learn,
easy-to-use Voice Office applications help increase productivity and
enhance organizational communications - without requiring any
integration work. For the hospitality sector, the Guest Services
applications provide additional services/features, generate revenue from
advertising on the phone screen, and reduce the cost of operations by
enabling guests to self serve. Custom development tools are also
available to end customers for delivery of customized content to IP
phones.

[source: http://www.nortel.com/ag2000]


Vulnerability overview:
-----------------------

The Nortel Application Gateway provides an administration interface
"Nortel Administration Tool powered by Citrix". This interface responds
with sensitive information to unauthorized users.


Vulnerability description:
--------------------------

The "Nortel Administration Tool powered by Citrix" can be accessed under
the URL "https://<server>:3001/". The subframe
"https://<server>:3001/adminDownloads.htm" does not show any content in
the browser view. However the HTML-source of this frame contains
sensitive information like an administrative call server user account:

---
<div id="call_server_host" value="10.11.12.13"></div> [...]
<div id="call_server_telnet_port" value="23"></div> [...]
<div id="call_server_user" value="admin123"></div>
<div id="call_server_pwd" value="hugo123"></div>
---


Proof of concept:
-----------------

This vulnerability can be exploited with a web browser and plugins / web
proxy.


Vendor contact timeline:
------------------------

January 2009: Vendor informed about vulnerability
2009-04-14: Patch available


Patch:
------

The vendor has released a vulnerability fix which addresses the issue.
In addition, the vendor has released a public security advisory
containing update instructions. URL:

http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=865005


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SEC Consult Unternehmensberatung GmbH

Office Vienna
Mooslackengasse 17
A-1190 Vienna
Austria

Tel.: +43 / 1 / 890 30 43 - 0
Fax.: +43 / 1 / 890 30 43 - 25
Mail: research at sec-consult dot com
www.sec-consult.com

EOF SEC Consult Vulnerability Lab / @2009
Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close