Vulnerability Name: | CVE-2007-1490 (CCN-33135) | ||||||||
Assigned: | 2007-03-06 | ||||||||
Published: | 2007-03-06 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection"). | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1490 Source: CCN Type: SA24434 Avaya Products Unspecified Shell Command Injection Source: SECUNIA Type: UNKNOWN 24434 Source: CONFIRM Type: Patch, Vendor Advisory http://support.avaya.com/elmodocs2/security/ASA-2007-052.htm Source: CCN Type: Avaya Web site VPNRemote Client Source: OSVDB Type: UNKNOWN 33300 Source: CCN Type: OSVDB ID: 33300 Avaya Multiple Products Unspecified Web Page Shell Command Injection Source: CCN Type: BID-22854 Avaya System Products Shell Command Injection Vulnerabilities Source: XF Type: UNKNOWN avaya-unspecified-command-execution(33135) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |