CVE Vulnerabilities

CVE-2013-7382

Published: May 17, 2014 | Modified: May 19, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for remote attackers to obtain access.

Affected Software

Name Vendor Start Version End Version
Vicidial Vicidial * 2.8 (including)
Vicidial Vicidial 2.7 (including) 2.7 (including)
Vicidial Vicidial 2.7-rc1 (including) 2.7-rc1 (including)

References