/
Security Issues

Security Issues

This page summarizes all known security issues, workarounds and fixes for the beroNet Gateway and Card Firmware. 

ISSUE: files can be downloaded with the GUI without a session

Date Found

The problem has been identified on 09.01.2017. 

Possible Effects

Users can download all files from the Filesystem, including the SIP configuration, the /etc/shadow file or the configuration database. If the attacker downloads the SIP Configuration he is able to make fraud calls. 

How to determine if the Firmware is affected? 

The problem exists in all firmwares 2.X and 3.X

Workaround & Precautions

To use this attack method http access to the gateway is required. Since in most use cases the gateway is behind a firewall, the http port should only be accessible by authorized administrators. The Firmware provides an ACL configuration. 

NOTE: if the attacker already gained access to the internal files it is required to change the passwords to make sure the attacker can't use the data anymore. 

Fixed Version

The security hole is fixed starting from the 3.0.16 and in all firmwares starting from 16.05. Please note an update to the 16.X-Beta Versions requires a Factory Reset. 

NOTE: please make sure to make a backup of your configuration before upgrading!

Related content

Updating your old beroNet Gateway to the latest beroNet OS
Updating your old beroNet Gateway to the latest beroNet OS
More like this
Tools and Downloads
Tools and Downloads
More like this
FAQ - Gateways & Card
FAQ - Gateways & Card
More like this
How to do a Hardware Factory Reset (Gateway V2 / SBC - VoIP Gateway)
How to do a Hardware Factory Reset (Gateway V2 / SBC - VoIP Gateway)
More like this
How to do a Hardware Factory Reset (Gateway and VoIP Card)
How to do a Hardware Factory Reset (Gateway and VoIP Card)
More like this
beroCAPI v21.03 and above
beroCAPI v21.03 and above
More like this

If you need scheduled remote assistance, you can request our on-demand support services: https://www.beronet.com/support