Hard-coded Cryptographic Key Vulnerability in Dialogic PowerMedia XMS Administrative Console

Hard-coded Cryptographic Key Vulnerability in Dialogic PowerMedia XMS Administrative Console

CVE-2018-11635 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.

Learn more about our Web Application Penetration Testing UK.