Auerswald COMsuite CTI application has been reported prone to weak default password vulnerability. It has been reported that, when installed, the CTI control center creates a user to enable operating system interaction. The password for this user account is easily guessed using readily available tools. Once the password is retrieved the "runasositron" account can be used locally and remotely to access the Windows PC on which COMsuite is installed.
Auerswald COMsuite CTI application has been reported prone to weak default password vulnerability. It has been reported that, when installed, the CTI control center creates a user to enable operating system interaction. The password for this user account is easily guessed using readily available tools. Once the password is retrieved the "runasositron" account can be used locally and remotely to access the Windows PC on which COMsuite is installed.