Vulnerability Name: | CVE-2008-3777 (CCN-44586) | ||||||||
Assigned: | 2008-08-19 | ||||||||
Published: | 2008-08-19 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-3777 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2008-347.htm Source: CCN Type: ASA-2008-347 Remote Administration Login Failure Vulnerabilities in Avaya SIP Enablement Services Server Source: CCN Type: Avaya Web site SIP Enablement Services Source: CCN Type: OSVDB ID: 49382 Avaya Multiple Products SIP Enablement Services (SES) Multiple Log Local Credentials Disclosure Source: BID Type: UNKNOWN 30758 Source: CCN Type: BID-30758 Avaya SES Authentication Bypass Vulnerability and Information Disclosure Weakness Source: XF Type: UNKNOWN avaya-ses-servers-info-disclosure(44586) Source: XF Type: UNKNOWN avaya-ses-servers-info-disclosure(44586) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |