Authentication Flaw in Avaya SIP Enablement Services Web Interface
CVE-2008-6707

Currently unrated

Key Information:

Vendor

Avaya

Vendor
CVE Published:
10 April 2009

What is CVE-2008-6707?

The web management interface of Avaya SIP Enablement Services versions 3.x and 4.0 lacks proper authentication for certain functionalities. This vulnerability allows remote attackers to gain unauthorized access to sensitive information and restricted capabilities. Attackers can exploit various entry points, including the certificate installation utility and default applications, to compromise server configuration data and other critical information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.