Dialogic XMS Default Login Scanner

This scanner checks the /admin endpoint of Dialogic XMS for default 'admin:admin' credentials, allowing attackers to gain full administrative control.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

1 minute

Time Interval

2 weeks 5 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

Dialogic XMS is a media server platform used by telecommunications companies and service providers to handle voice, video, and messaging processing. The Admin Console provides a web-based interface for administrators to configure network settings, manage user accounts, and monitor system performance. It is essential for managing distributed media processing environments efficiently.

The default login vulnerability arises when the Dialogic XMS Admin Console is deployed without changing the factory-set credentials. This security misconfiguration allows anyone with network access to authenticate using well-known default usernames and passwords, such as 'admin:admin'. Attackers often scan for such weaknesses to gain unauthorized entry.

Specifically, the vulnerability is present in the login endpoint of the Admin Console, typically accessed via HTTP POST requests to /admin or similar paths. The application fails to enforce a mandatory password change upon first login, leaving the default credentials active. This oversight enables attackers to bypass authentication entirely.

If exploited, an attacker can gain full administrative access to the Dialogic XMS server, allowing them to modify configurations, intercept media streams, disrupt services, or pivot to other network resources. This can lead to significant operational downtime, data breaches, and reputational damage for the affected organization.

Get started to protecting your digital assets