Cleartext Data Vulnerability in Avaya IP Office Products
CVE-2005-0506

Currently unrated

Key Information:

Vendor
Avaya
Vendor
CVE Published:
14 March 2005

Summary

The Avaya IP Office Phone Manager and associated products, including the IP Softphone, face a vulnerability where sensitive information such as usernames and passwords is stored in cleartext within a registry key. This exposure permits both local and potentially remote users to gain unauthorized access to the sensitive data, enabling impersonation of legitimate users. The registry keys identified include paths such as Avaya\IP400\Generic, further highlighting the risk of data theft.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.