The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2002-07-15T04:00:00

Updated: 2024-08-08T02:56:38.488Z

Reserved: 2002-07-09T00:00:00

Link: CVE-2002-0670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2002-07-23T04:00:00.000

Modified: 2008-09-05T20:28:38.227

Link: CVE-2002-0670

cve-icon Redhat

No data.