6.4
CVSSv2

CVE-2008-6707

Published: 10/04/2009 Updated: 17/08/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote malicious users to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."

Vulnerable Product Search on Vulmon Subscribe to Product

avaya sip_enablement_services 4.0

avaya sip_enablement_services 3.1.1

avaya sip_enablement_services 3.0

avaya sip_enablement_services 3.1

avaya communication_manager 3.1.5

avaya communication_manager 3.1.3

avaya communication_manager 3.1.1

avaya communication_manager 3.1.4

avaya communication_manager 3.1

avaya communication_manager 3.1.2