Synopsis
The remote device is affected by an information disclosure vulnerability
Description
The remote Grandstream phone is affected by an information disclosure vulnerability in the web administration interface due to the failure to restrict access to sensitive configuration data. An unauthenticated, remote attacker can exploit this to disclose sensitive information related to the device, such as the admin password.
Solution
Upgrade to the latest firmware verison.
Plugin Details
File Name: grandstream_get_password.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: installed_sw/Grandstream Phone
Exploited by Nessus: true
Patch Publication Date: 11/9/2015
Vulnerability Publication Date: 11/9/2015