![]() |
Information leak vulnerability in Snom-320 SIP Phone may allow access to use’s call records
OverviewAn information leak vulnerability in Snom-320 SIP phone may allow a remote third party to gain access to user’s private call data records. ImpactUser’s privacy is compromised due to un-authenticated access to the call data records through http. This may happen without the knowledge of the user. Description
Snom-320 SIP phone is a remote-manageable and firmware-upgradeable SIP business telephone. It uses SIP protocol to provide VoIP services to business users. Snom-320 has a built-in web server which supports end-user configuration. The built-in web server listens on standard http port 80. In addition to port 80, Snom-320 phone has TCP port 1800 open and accessible through http. Accessing port 1800 through a web-browser displays following information without asking for any password (formatted for readability)— Received Calls Dialed Numbers This allows a remote malicious third party to gain access to user’s private call records. Solution
Phone web-server implementation should be patched to authenticate users accessing port 1800. Vendor response: Snom: More information about the solution is available at http://snom.com/wiki/index.php/Snom320/Firmware/Release_Notes#7.1.6_beta. For more information on any of these threat advisories, please email Sipera VIPER Lab at viper@sipera.com |
UC Security Defined
Sipera Systems, the leader in real-time Unified
Communications (UC) security, is the choice of enterprises
and service providers around the world to support their
mission-critical UC deployments.
Sipera offers groundbreaking, production-proven solutions
that secure voice, video, messaging, collaboration, and
other real-time communications in converged IP networks,
boosting compliance with information security requirements.
Backed by the industry-leading research of the VIPER lab,
Sipera's solutions provide comprehensive threat protection,
policy enforcement, access control, and encryption in a
single flexible appliance.