CVE-2008-6709
Last modified
CVE-2008-6709 is a vulnerability of currently unknown severity. Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters.". EPSS estimates a 2.44% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Sip Enablement Services | 3.0 |
| Avaya | Sip Enablement Services | 3.1 |
| Avaya | Sip Enablement Services | 3.1.1 |
| Avaya | Sip Enablement Services | 4.0 |
| Avaya | Communication Manager | 3.1 |
| Avaya | Communication Manager | 3.1.1 |
| Avaya | Communication Manager | 3.1.2 |
| Avaya | Communication Manager | 3.1.3 |
| Avaya | Communication Manager | 3.1.4 |
| Avaya | Communication Manager | 3.1.5 |
References
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htmVendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htmVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-6709?
How severe is CVE-2008-6709?
How do I fix CVE-2008-6709?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-6703Stack-based buffer overflow in the IPureServer::_Recieve fun…
- CVE-2008-6704Integer overflow in the NET_Compressor::Decompress function …
- CVE-2008-6705The MultipacketReciever::RecievePacket function in S.T.A.L.K…
- CVE-2008-6706Multiple unspecified vulnerabilities in the Web management i…
- CVE-2008-6707The Web management interface in Avaya SIP Enablement Service…
- CVE-2008-6708Unspecified vulnerability in the Web management interface in…
- CVE-2008-6710Unspecified vulnerability in the Web administration interfac…
- CVE-2008-6711Unspecified vulnerability in the Web administration interfac…
- CVE-2008-6712The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.…
- CVE-2008-6713World in Conflict (WIC) 1.008 and earlier allows remote atta…
- CVE-2008-6714admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attac…
- CVE-2008-6715Multiple cross-site scripting (XSS) vulnerabilities in Pre A…
Are you affected by CVE-2008-6709?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
