CVE-2008-6706
Last modified
CVE-2008-6706 is a vulnerability of currently unknown severity. Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system utility that decrypts "subscriber table passwords," (4) a system utility that decrypts database passwords, and (5) a system utility that encrypts "subscriber table passwords.". EPSS estimates a 2.26% chance of exploitation in the next 30 days.
Description
Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system utility that decrypts "subscriber table passwords," (4) a system utility that decrypts database passwords, and (5) a system utility that encrypts "subscriber table passwords."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Sip Enablement Services | 3.0 |
| Avaya | Sip Enablement Services | 3.1 |
| Avaya | Sip Enablement Services | 3.1.1 |
| Avaya | Sip Enablement Services | 4.0 |
| Avaya | Communication Manager | 3.1 |
| Avaya | Communication Manager | 3.1.1 |
| Avaya | Communication Manager | 3.1.2 |
| Avaya | Communication Manager | 3.1.3 |
| Avaya | Communication Manager | 3.1.4 |
| Avaya | Communication Manager | 3.1.5 |
References
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htmVendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htmVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-6706?
How severe is CVE-2008-6706?
How do I fix CVE-2008-6706?
Are you affected by CVE-2008-6706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
