NVD

Id
85119  
Name
CVE-2016-1518  
Description
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/.  
Reject
 
CVSS Version
 
CVSS Score
 
Severity
 
CVSS Base Score
 
CVSS Impact Subscore
 
CVSS Exploit Subscore
 
CVSS Vector
 
Pub Date
2017-04-27  
Published
2017-04-21  
Modified Date
2017-04-21  
Seq
2016-1518  

Actions