Title: Vulnerability Report For Voyant Technologies Sonata Conferencing product |
Author: Larry W. Cashdollar, @_larry0 |
Date: 2000-10-31 |
CVE-ID:[CVE-none] |
CWE: |
Download Site: http://www.voyanttechnology.com/ |
Vendor: Voyant Technologies. |
Vendor Notified: 2000-10-13 |
Vendor Contact: vulnhelp@securityfocus.com |
Advisory: http://www.vapid.dhs.org/advisories/voyant_technologies_sonata_vulnerabilities.html |
Description: Sonata is a teleconfrencing solution developed by Voyant Technologies. This advisory concerns the Sonata application server and bridge componet of the Sonata package. The application server is an Ultra Sparc 5 running Solaris 2.x as required by Voyant technologies. The bridge is an IBM PC running OS/2 Warp. These hosts are usually built in house by Voyant personnel and installed at customer locations by a field engineer. |
Vulnerability: Six vulnerabilities have been found in the application server host and Sonata package, they are categorized below:
Reused default user accounts and passwords.
Easily guessable passwords.
Poor file permissions.
Lack of host hardening.
X console authentication has been disabled.
Hard coded default passwords.
Sonata v3.x on Solaris 2.x.
Sonata bridge OS/2 Warp. |
Export: JSON TEXT XML |
Exploit Code:
|
Screen Shots: |
Notes: 91319 |
Larry W. Cashdollar
Larry Cashdollar
Larry W. Cashdollar vulnerability
Larry Cashdollar advisory