|
SEC Consult Security Advisory < 20090415-1 >
========================================================================= title: Nortel Application Gateway 2000 Password
Disclosure Vulnerability
program: Nortel Application Gateway 2000
vulnerable version: 6.3.1 and prior
homepage: http://www.nortel.com/ag2000
found: 2008-11-14
by: David Matscheko / SEC Consult / www.sec-consult.com
link:
https://www.sec-consult.com/files/20090415-1_nortel_AG_password_disclosure.txt
=========================================================================
Vendor description:
-------------------
The Application Gateway delivers practical, converged voice and data
applications on Nortel IP phones that enable organizations to benefit
more fully from IP telephony. The prepackaged, easy-to-learn,
easy-to-use Voice Office applications help increase productivity and
enhance organizational communications - without requiring any
integration work. For the hospitality sector, the Guest Services
applications provide additional services/features, generate revenue from
advertising on the phone screen, and reduce the cost of operations by
enabling guests to self serve. Custom development tools are also
available to end customers for delivery of customized content to IP
phones.
[source: http://www.nortel.com/ag2000]
Vulnerability overview:
-----------------------
The Nortel Application Gateway provides an administration interface
"Nortel Administration Tool powered by Citrix". This interface responds
with sensitive information to unauthorized users.
Vulnerability description:
--------------------------
The "Nortel Administration Tool powered by Citrix" can be accessed under
the URL "https://