CVE-2011-3008
The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by…
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as demonstrated by alarm and log information.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- avaya/secure access link gateway
- Source
- cve@mitre.org
References
- http://support.avaya.com/css/P8/documents/100140483Vendor Advisory
- http://www.kb.cert.org/vuls/id/690315US Government Resource
- http://www.securityfocus.com/bid/48942
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68922
- http://support.avaya.com/css/P8/documents/100140483Vendor Advisory
- http://www.kb.cert.org/vuls/id/690315US Government Resource
- http://www.securityfocus.com/bid/48942
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68922
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.