7.5

CVE-2019-9228

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AudiocodesMedian 500l-msbr Firmware Version >= f7.20a <= f7.20a.252.062
   AudiocodesMedian 500l-msbr Version-
AudiocodesMedian 500-msbr Firmware Version >= f7.20a <= f7.20a.252.062
   AudiocodesMedian 500-msbr Version-
AudiocodesMedian M800b-msbr Firmware Version >= f7.20a <= f7.20a.252.062
   AudiocodesMedian M800b-msbr Version-
AudiocodesMedian 800c-msbr Firmware Version >= f7.20a <= f7.20a.252.062
   AudiocodesMedian 800c-msbr Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.657
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P