Release date:
Updated on:
Affected Systems:
Enghouseinteractive Enghouse Interactive IVR Pro
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65000
CVE (CAN) ID: CVE-2013-6838
Enghouse Interactive IVR Pro is the call center software.
Enghouse Interactive IVR Pro 9.0.3 and other versions allow unauthenticated users to bypass authentication and Log On As root users, resulting in full control of the affected devices.
<* Source: Fredrik Soderblom
Link: http://seclists.org/fulldisclosure/2014/Jan/103? Utm_source = twitterfeed & utm_medium = twitter
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Enghouseinteractive
-------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://enghouseinteractive.se/ivr-pro-2? Lang = en
Https://xpd.se/advisories/xpd-disclosure-policy-01.txt