7.2
CVE-2002-0674
- EPSS 0.38%
- Veröffentlicht 23.07.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:57:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.294 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://www.atstake.com/research/advisories/2002/a071202-1.txt
http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp
http://www.securityfocus.com/bid/5221
https://exchange.xforce.ibmcloud.com/vulnerabilities/9569