Asterisk Recording Interface (ARI) Default Administrator Credentials

high Nessus Plugin ID 44872

Synopsis

A web application is protected using default administrator credentials.

Description

The remote web server hosts Asterisk Recording Interface (ARI), which provides a web-enabled interface for Asterisk users to manage their voicemail and phone features.

The remote installation of ARI uses a default set of credentials for the administrator's account. With this information, an attacker can gain administrative access to the application.

Solution

Edit the application's 'includes/main.conf.php' file and change the values for '$ARI_ADMIN_USERNAME' and/or '$ARI_ADMIN_PASSWORD'.

Plugin Details

Severity: High

ID: 44872

File Name: ari_default_creds.nasl

Version: 1.13

Type: remote

Family: CGI abuses

Published: 2/23/2010

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

Excluded KB Items: global_settings/supplied_logins_only