topleft topright
VoIPshield System stopped publishing new vulnerabilities as of November 2008. If you are interested in newest VoIP vulnerabilities please send an email to info@voipshield.com.

  

Use the Search field or Category and Vendor filters to navigate the database of vulnerabilities. Click vulnerability for details.

Severity Tracking ID Category Vendor Product Released Response
Unauthenticated Cisco Serviceability Access
2 VSRCS-2008-003 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
Unauthenticated Plugin Access
2 VSRCS-2008-003 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
Unauthenticated Call Server Link Access
1 VSRCS-2008-003 Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
Unauthenticated pktCap Access
1 VSRCS-2008-003 Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
Unauthenticated License File Access
2 VSRCS-2008-003 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
Unencrypted Authenticated Access
1 VSRCS-2008-003 Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
Unauthenticated Balancer Access
1 VSRCS-2008-003 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
SKINNY Registration DoS
4 VSRCS-2008-004 Denial of Service Cisco Call Manager 4.1.x 2008-04-01 patch
DRF Get Features List Command Injection
2 VSRCS-2008-002 Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Version Command Injection
1 VSRCS-2008-002 Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
Multiple Command Injection Vulnerabilities
4 VSRNT-2008-005 Unauthorized Access Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
DRF Cancel Backup Command Injection
4 VSRCS-2008-002 Denial of Service Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Save Backup Features Command Injection
4 VSRCS-2008-002 Denial of Service Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Restore Command Directory Creation
4 VSRCS-2008-002 Code Execution Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Get Features List Command Overflow
4 VSRCS-2008-002 Code Execution Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Change Destination Command Injection
4 VSRCS-2008-002 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Restore Command Injection
4 VSRCS-2008-002 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Execute Backup Command Injection
3 VSRCS-2008-002 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
Unauthenticated Extension Mobility Web Access
1 VSRCS-2008-003 Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
DRF List Backup File Existence Flaw
2 VSRCS-2008-002 Information Gathering Cisco Unified Communications Manager 5.x 2008-04-01 patch
<< Start < Previous Next > End >>
Display # Results 21 - 40 of 97
 

Each line represents an individual vulnerability or group of vulnerabilities. For example, "UCM Multiple Hardcoded Passwords" is presented here in a single line but was reported to Nortel as sixteen (16) individual vulnerabilities.

Severity Legend

Click on a level for description
Low

A low severity issue falls into one of two categories.  Firstly, there are those that are not directly exploitable and affect a single IP client, a small subset of the deployment, or are quite innocuous taken by themselves. In other words, they provide information which either involves only a small number (or single) client and that information requires considerable other information or effort to be useful to an attacker.  The other category of low severity issues includes those that are best practices which are not intended to directly mitigate an exploitable risk but to increase overall security robustness and demonstrate due diligence.

Medium

A medium severity issue is typically an issue which can lead to further exploitation or provides short-lived effect on a minimal number of clients.  It may not be immediately exploitable but provides sufficient information or access to move an attack closer to fruition.  Alternately it may provide unauthorized access not directly related to the VoIP portion of the network.

High

A high severity issue can be exploited to compromise one or more nodes within the deployment but may require authentication, especially when exploiting multiple systems simultaneously. In addition, it may be possible to protect against untrusted exploitation of the issue by deploying traditional security tools.

Critical

A critical severity issue can be exploited by an untrusted individual to compromise the entire deployment under review.  There are no security or protective mechanisms in place that will mediate exploitation of this vulnerability by an untrusted individual.

Vendor Response Legend

Patch available
Workaround proposed
Attempting to address the issue
No vendor response
Copyright © VoIPshield Systems Inc. All rights reserved.