Passwords are used in FreeSWITCH when phones register, when phones originate a call, when FreeSWITCH registers to external gateways/ITSPs and when administrators authenticate into the FreeSWITCH system via Event Socket (eg: fs_cli). Most of these areas utilize weak plaintext passwords.
In addition, many users set their passwords to simple easy-to-guess combinations. Worse yet, some don't ever change or set up their voicemail password, leaving the defaults in place.
These passwords are very often targeted and once gained, they are exploited to commit fraud.
Following are some of the mechanisms available to mitigate this.