The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.
References
Configurations
History
21 Nov 2024, 00:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://support.avaya.com/elmodocs2/security/ASA-2008-347.htm - | |
References | () http://www.securityfocus.com/bid/30758 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/44586 - |
Information
Published : 2008-08-25 21:41
Updated : 2024-11-21 00:50
NVD link : CVE-2008-3777
Mitre link : CVE-2008-3777
CVE.ORG link : CVE-2008-3777
JSON object : View
Products Affected
avaya
- sip_enablement_services
- s8300c_server
- communication_manager
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor