Meridian Integrated Personal Call Director Password Disclosure

Published on 02 Jul 2018
Vulnerability

Meridian Integrated Personal Call Director (MIPCD) is used by users to redirect calls from any person to any mobile phone or landline. MIPCD continues to forward calls tell anyone picks up or all the options are exhausted. The MIPCD can be used to set rules for call forwarding for mobile phones and FAX machines. The Meridian Integrated Personal Call Director contained a bug due to which, an attacker can expose MIPCD to gain unauthorised password exposure. The attacker can gain remote access to the login, password and user config files through the web interface. These files contain the usernames and passwords of all the MIPCD users and might also include credentials of the administrator account. This vulnerability poses a huge risk to the security of the web application.

Impact

The impact include:-

  • Access to unauthorised content
  • Loss of sensitive data.
  • Possible data manipulation.

Mitigation / Precaution

Beagle recommends the following fixes:-

  • Upgrade MIPCD to the latest version ( 1.5 or higher).
Jijith Rajan
Written by
Cyber Security Engineer

His passion for staying abreast of the latest security threats and trends, coupled with his hands-on experience, allows him to actively contribute to the protection of digital assets. Jijith's dedication and enthusiasm make him a promising talent in the ever-evolving realm of cybersecurity, promising a safer digital future.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo