topleft
topright
advanced search...

Severity Title Category Vendor Product Released Response
3 IM SMS Route Privilege Elevation Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
3 IM SMS Hostname Privilege Elevation Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
4 UCM Multiple Hardcoded Passwords Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
4 CS1000 Multiple Hardcoded Passwords Unauthorized Access Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
2 IM SMS Ping Code Execution Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
4 CS1000 FTP Session Limit Exhaustion Denial of Service Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
2 IM SMS System Time Code Execution Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
2 IM SMS Log Viewer Code Execution Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
3 IM SMS Arbitrary File Deletion Unauthorized Access Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
2 IM SMS File Existence Flaw Unauthorized Access Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
3 SES SIP SQL Injection Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
3 SES SIP SQL Denial of Service Denial of Service Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
4 SES SIP Credential Reuse Unauthorized Access Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
4 SPIM Unauthenticated SQL Injection Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
3 SPIM Permissions SQL Injection Code Execution Avaya Communications Manager 3.1.x and 4.x 2008-04-01 att_issue
4 Nortel UNIStim IT Sequence Number Intercept Unauthorized Access Nortel UNIStim Clients and Servers 2008-04-01 patch
1 Web Application Structure Disclosure Information Gathering Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
4 Multiple Command Injection Vulnerabilities Unauthorized Access Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
4 DRF Cancel Backup Command Injection Denial of Service Cisco Unified Communications Manager 5.x 2008-04-01 patch
4 DRF Save Backup Features Command Injection Denial of Service Cisco Unified Communications Manager 5.x 2008-04-01 patch
4 DRF Restore Command Directory Creation Code Execution Cisco Unified Communications Manager 5.x 2008-04-01 patch
4 DRF Get Features List Command Overflow Code Execution Cisco Unified Communications Manager 5.x 2008-04-01 patch
4 DRF Change Destination Command Injection Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
4 DRF Restore Command Injection Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
3 DRF Execute Backup Command Injection Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
2 DRF List Backup File Existence Flaw Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
3 DRF Get Destination Command Injection Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
2 DRF Show History Command Injection Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
1 DRF Version Command Injection Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
2 DRF Get Features List Command Injection Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
1 DRF Get Registration Command Injection Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
1 DRF Get Schedule Command Injection Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
3 Address Book SQL Injection Code Execution Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
2 Unauthenticated Alarm Application Access Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
2 Unauthenticated Cisco Serviceability Access Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
2 Unauthenticated Plugin Access Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
1 Unauthenticated Call Server Link Access Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
1 Unauthenticated pktCap Access Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
2 Unauthenticated License File Access Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
1 Unauthenticated Extension Mobility Web Access Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
1 Unencrypted Authenticated Access Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
1 Unauthenticated Balancer Access Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
4 SKINNY Registration DoS Denial of Service Cisco Call Manager 4.1.x 2008-04-01 patch
4 Unauthenticated Call Flooding Denial of Service Cisco Call Manager 4.1.x 2008-04-01 patch
<< Start < Previous 1 Next > End >>
Display # Results 1 - 44 of 44
Each line represents an individual vulnerability or group of vulnerabilities.  For example, “CS1000 Multiple Hardcoded Passwords” is presented here in a single line but was reported to Nortel as sixteen (16) individual vulnerabilities.

Severity Legend

Click on a level for description
Low

A low severity issue falls into one of two categories.  Firstly, there are those that are not directly exploitable and affect a single IP client, a small subset of the deployment, or are quite innocuous taken by themselves. In other words, they provide information which either involves only a small number (or single) client and that information requires considerable other information or effort to be useful to an attacker.  The other category of low severity issues includes those that are best practices which are not intended to directly mitigate an exploitable risk but to increase overall security robustness and demonstrate due diligence.

Read More

Medium

A medium severity issue is typically an issue which can lead to further exploitation or provides short-lived effect on a minimal number of clients.  It may not be immediately exploitable but provides sufficient information or access to move an attack closer to fruition.  Alternately it may provide unauthorized access not directly related to the VoIP portion of the network.

Read More

High

A high severity issue can be exploited to compromise one or more nodes within the deployment but may require authentication, especially when exploiting multiple systems simultaneously. In addition, it may be possible to protect against untrusted exploitation of the issue by deploying traditional security tools.

Read More

Critical

A critical severity issue can be exploited by an untrusted individual to compromise the entire deployment under review.  There are no security or protective mechanisms in place that will mediate exploitation of this vulnerability by an untrusted individual.

Read More

Vendor Response Legend

Patch available
Workaround proposed
Attempting to address the issue
No vendor response
1-866-229-6589 | info@voipshield.com
Copyright © VoIPshield Systems Inc. All rights reserved.
Joomla Templates by JoomlaShack Joomla Templates