CVE-2018-11518
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone call, an attacker can record these frequencies and use them for service activations. This is a request-forgery issue when the required series of DTMF signals for a service activation is predictable (e.g., the IVR system does not speak a nonce to the caller). In this case, the IVR system accepts an activation request from a less-secure channel (any loudspeaker in the caller's physical environment) without verifying that the request was intended (it matches a nonce sent over a more-secure channel to the caller's earpiece).
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- hcltech/legacy ivr firmware
- Source
- cve@mitre.org
References
- http://virgil-cj.blogspot.com/2018/05/0day-legacy-ivr-lets-phreak.htmlThird Party Advisory
- https://datarift.blogspot.com/2018/05/CVE-2018-11518-abusing-ivr-systems.htmlThird Party Advisory
- https://twitter.com/mishradhiraj_/status/1001664204485652482Third Party Advisory
- https://twitter.com/mishradhiraj_/status/1001664440759091207Third Party Advisory
- http://virgil-cj.blogspot.com/2018/05/0day-legacy-ivr-lets-phreak.htmlThird Party Advisory
- https://datarift.blogspot.com/2018/05/CVE-2018-11518-abusing-ivr-systems.htmlThird Party Advisory
- https://twitter.com/mishradhiraj_/status/1001664204485652482Third Party Advisory
- https://twitter.com/mishradhiraj_/status/1001664440759091207Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.