o2 DSL Auto Configuration Server Credential Disclosure

Discussion in 'News Aggregator' started by Packet Storm, 9 Jan 2016.

  1. Packet Storm

    Packet Storm Guest

    The o2 Auto Configuration Server (ACS) discloses VoIP/SIP credentials of arbitrary customers when receiving manipulated CWMP packets. These credentials can then be used by an attacker to register any VoIP number of the victim. This enables the attacker to place and receive calls on behalf of the attacked user.

    Continue reading...
     

Share This Page

Loading...