6.4
CVE-2008-6707
- EPSS 1.5%
- Veröffentlicht 10.04.2009 22:00:00
- Zuletzt bearbeitet 16.06.2026 23:02:48
- Erkennungen
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Avaya ≫ Sip Enablement Services Version 3.0
Avaya ≫ Sip Enablement Services Version 3.1
Avaya ≫ Sip Enablement Services Version 3.1.1
Avaya ≫ Sip Enablement Services Version 4.0
Avaya ≫ Communication Manager Version 3.1
Avaya ≫ Communication Manager Version 3.1.1
Avaya ≫ Communication Manager Version 3.1.2
Avaya ≫ Communication Manager Version 3.1.3
Avaya ≫ Communication Manager Version 3.1.4
Avaya ≫ Communication Manager Version 3.1.4 Update sp1
Avaya ≫ Communication Manager Version 3.1.4 Update sp2
Avaya ≫ Communication Manager Version 3.1.5
Avaya ≫ Communication Manager Version 3.1.5 Update sp0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.5% | 0.709 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://secunia.com/advisories/30751
http://support.avaya.com/elmodocs2/security/ASA-2008-268.htm
http://www.securityfocus.com/bid/29939
http://www.vupen.com/english/advisories/2008/1943/references
http://osvdb.org/46598
http://osvdb.org/46599
http://osvdb.org/46600
http://www.voipshield.com/research-details.php?id=86
http://www.voipshield.com/research-details.php?id=87
http://www.voipshield.com/research-details.php?id=88
http://www.voipshield.com/research-details.php?id=89
http://www.voipshield.com/research-details.php?id=90
http://www.voipshield.com/research-details.php?id=91
https://exchange.xforce.ibmcloud.com/vulnerabilities/43381
https://exchange.xforce.ibmcloud.com/vulnerabilities/43384
https://exchange.xforce.ibmcloud.com/vulnerabilities/43389
https://exchange.xforce.ibmcloud.com/vulnerabilities/43393
https://exchange.xforce.ibmcloud.com/vulnerabilities/43394
https://exchange.xforce.ibmcloud.com/vulnerabilities/43395