CVE-2008-6707
Last modified
CVE-2008-6707 is a vulnerability of currently unknown severity. The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help.". EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Sip Enablement Services | 3.0 |
| Avaya | Sip Enablement Services | 3.1 |
| Avaya | Sip Enablement Services | 3.1.1 |
| Avaya | Sip Enablement Services | 4.0 |
| Avaya | Communication Manager | 3.1 |
| Avaya | Communication Manager | 3.1.1 |
| Avaya | Communication Manager | 3.1.2 |
| Avaya | Communication Manager | 3.1.3 |
| Avaya | Communication Manager | 3.1.4 |
| Avaya | Communication Manager | 3.1.5 |
References
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htmVendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htmVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-6707?
How severe is CVE-2008-6707?
How do I fix CVE-2008-6707?
Are you affected by CVE-2008-6707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
