SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-6707

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and…

MEDIUM 6.4EPSS 1.50%

Does this matter?

Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.

Description

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
1.50% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
avaya/sip enablement services · avaya/communication manager
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.