10
CVSSv2

CVE-2013-6838

Published: 28/01/2014 Updated: 31/01/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers' installations, which allows remote malicious users to gain privileges by leveraging knowledge of this key.

Vulnerable Product Search on Vulmon Subscribe to Product

enghouseinteractive ivr_pro 9.0.3

Exploits

Enghouse Interactive IVR Pro (VIP2000) suffers from a remote root authentication bypass vulnerability due to a backdoor private/public ssh key being on the systems ...