Privilege Escalation and Denial of Service in Avaya Communication Manager Services
CVE-2008-6574

Currently unrated

Key Information:

Vendor

Avaya

Vendor
CVE Published:
1 April 2009

What is CVE-2008-6574?

An unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager versions 3.1.x and 4.x allows remote attackers to exploit valid credentials for unauthorized privilege escalation. This could lead to a denial of service as attackers manipulate device access governed by credential validation mechanisms. The exact vectors exploited remain unknown, increasing the risk for organizations using these affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.