Privilege Escalation and Denial of Service in Avaya Communication Manager Services
CVE-2008-6574

Currently unrated

Key Information:

Vendor
Avaya
Vendor
CVE Published:
1 April 2009

Summary

An unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager versions 3.1.x and 4.x allows remote attackers to exploit valid credentials for unauthorized privilege escalation. This could lead to a denial of service as attackers manipulate device access governed by credential validation mechanisms. The exact vectors exploited remain unknown, increasing the risk for organizations using these affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.