Dialogic XMS Default Login Scanner
This scanner checks the /admin endpoint of Dialogic XMS for default 'admin:admin' credentials, allowing attackers to gain full administrative control.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
1 minute
Time Interval
2 weeks 5 hours
Scan only one
Domain, IPv4, Subdomain
Toolbox
Dialogic XMS is a media server platform used by telecommunications companies and service providers to handle voice, video, and messaging processing. The Admin Console provides a web-based interface for administrators to configure network settings, manage user accounts, and monitor system performance. It is essential for managing distributed media processing environments efficiently.
The default login vulnerability arises when the Dialogic XMS Admin Console is deployed without changing the factory-set credentials. This security misconfiguration allows anyone with network access to authenticate using well-known default usernames and passwords, such as 'admin:admin'. Attackers often scan for such weaknesses to gain unauthorized entry.
Specifically, the vulnerability is present in the login endpoint of the Admin Console, typically accessed via HTTP POST requests to /admin or similar paths. The application fails to enforce a mandatory password change upon first login, leaving the default credentials active. This oversight enables attackers to bypass authentication entirely.
If exploited, an attacker can gain full administrative access to the Dialogic XMS server, allowing them to modify configurations, intercept media streams, disrupt services, or pivot to other network resources. This can lead to significant operational downtime, data breaches, and reputational damage for the affected organization.