|
224451
|
9.8 |
CRITICAL
Network
|
nec
|
sv8100_firmware
|
On Aspire-derived NEC PBXes, including all versions of SV8100 devices, a set of documented, static login credentials may be used to access the DIM interface.
|
CWE-287
Improper Authentication
|
CVE-2019-20033
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224452
|
6.5 |
MEDIUM
Network
|
nec
|
sv8100_firmware sv9100_firmware sl1100_firmware sl2100_firmware
|
An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices, may ac…
|
NVD-CWE-noinfo
|
CVE-2019-20032
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224453
|
9.1 |
CRITICAL
Network
|
nec
|
um8000_firmware um4730_firmware
|
NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing …
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-20031
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224454
|
7.8 |
HIGH
Local
|
nec
|
um8000_firmware
|
An attacker with knowledge of the modem access number on a NEC UM8000 voicemail system may use SSH tunneling or standard Linux utilities to gain access to the system's LAN port. All versions are affe…
|
NVD-CWE-noinfo
|
CVE-2019-20030
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224455
|
8.8 |
HIGH
Network
|
nec
|
sv8100_firmware sv9100_firmware sl1100_firmware sl2100_firmware
|
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially craf…
|
NVD-CWE-noinfo
|
CVE-2019-20029
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224456
|
7.5 |
HIGH
Network
|
nec
|
sv8100_firmware sv9100_firmware sl1100_firmware sl2100_firmware
|
Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice resp…
|
NVD-CWE-noinfo
|
CVE-2019-20028
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224457
|
9.8 |
CRITICAL
Network
|
nec
|
sv8100_firmware sv9100_firmware sl1100_firmware sl2100_firmware
|
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password…
|
CWE-287
Improper Authentication
|
CVE-2019-20027
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224458
|
7.5 |
HIGH
Network
|
nec
|
sv9100_firmware
|
The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.
|
NVD-CWE-noinfo
|
CVE-2019-20026
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224459
|
9.8 |
CRITICAL
Network
|
nec
|
sv9100_firmware
|
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-20025
|
2024-11-21 13:37 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224460
|
7.8 |
HIGH
Local
|
solarwinds
|
webhelpdesk
|
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a Tic…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-20002
|
2024-11-21 13:37 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|