topleft topright
VoIPshield System stopped publishing new vulnerabilities as of November 2008. If you are interested in newest VoIP vulnerabilities please send an email to info@voipshield.com.

    

Use the Search field or Category and Vendor filters to navigate the database of vulnerabilities. Click vulnerability for details.

Severity Tracking ID Category Vendor Product Released Response
CS1000 Oversized Command DoS
4 VSRNT-2008-006 Denial of Service Nortel Communications Server 1000 4.50.x 2008-06-25 att_issue
MCS5100 Wireless Client Manager Session Initiation Protocol Proxy DoS
4 VSRNT-2008-008 Denial of Service Nortel Multimedia Communications Server 5100 3.x 2008-06-25 workaround
Call Manager CTIManager DoS
4 VSRCS-2008-005 Denial of Service Cisco Call Manager 4.x, Unified Communications Manager 5.x, Unified Communications Manager 6.x 2008-06-25 patch
Unified Communications Manager CTIManager DoS
4 VSRCS-2008-005 Denial of Service Cisco Unified Communications Manager 5.x, Unified Communications Manager 6.x 2008-06-25 patch
SIP Enablement Service Web Interface Database Server Configuration Disclosure
4 VSRAV-2008-004 Unauthorized Access Avaya Communication Manager 3.1.x 2008-06-25 att_issue
SES SIP Credential Reuse
4 VSRAV-2008-002 Unauthorized Access Avaya Communication Manager 3.1.x, Communication Manager 4.x 2008-04-01 workaround
UCM Multiple Hardcoded Passwords
4 VSRCS-2008-001 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 att_issue
CS1000 Multiple Hardcoded Passwords
4 VSRNT-2008-003 Unauthorized Access Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
CS1000 FTP Session Limit Exhaustion
4 VSRNT-2008-001 Denial of Service Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
SPIM Unauthenticated SQL Injection
4 VSRAV-2008-003 Code Execution Avaya Communication Manager 3.1.x, Communication Manager 4.x 2008-04-01 workaround
Nortel UNIStim IT Sequence Number Intercept
4 VSRNT-2008-002 Unauthorized Access Nortel UNIStim Clients and Servers 2008-04-01 patch
SKINNY Registration DoS
4 VSRCS-2008-004 Denial of Service Cisco Call Manager 4.1.x 2008-04-01 patch
Multiple Command Injection Vulnerabilities
4 VSRNT-2008-005 Unauthorized Access Nortel Communications Server 1000 4.50.x 2008-04-01 att_issue
DRF Cancel Backup Command Injection
4 VSRCS-2008-002 Denial of Service Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Save Backup Features Command Injection
4 VSRCS-2008-002 Denial of Service Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Restore Command Directory Creation
4 VSRCS-2008-002 Code Execution Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Get Features List Command Overflow
4 VSRCS-2008-002 Code Execution Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Change Destination Command Injection
4 VSRCS-2008-002 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
DRF Restore Command Injection
4 VSRCS-2008-002 Unauthorized Access Cisco Unified Communications Manager 5.x 2008-04-01 patch
Unauthenticated Call Flooding
4 VSRCS-2008-004 Denial of Service Cisco Call Manager 4.1.x 2008-04-01 patch
<< Start < Previous Next > End >>
Display # Results 1 - 20 of 97
 

Each line represents an individual vulnerability or group of vulnerabilities. For example, "UCM Multiple Hardcoded Passwords" is presented here in a single line but was reported to Nortel as sixteen (16) individual vulnerabilities.

Severity Legend

Click on a level for description
Low

A low severity issue falls into one of two categories.  Firstly, there are those that are not directly exploitable and affect a single IP client, a small subset of the deployment, or are quite innocuous taken by themselves. In other words, they provide information which either involves only a small number (or single) client and that information requires considerable other information or effort to be useful to an attacker.  The other category of low severity issues includes those that are best practices which are not intended to directly mitigate an exploitable risk but to increase overall security robustness and demonstrate due diligence.

Medium

A medium severity issue is typically an issue which can lead to further exploitation or provides short-lived effect on a minimal number of clients.  It may not be immediately exploitable but provides sufficient information or access to move an attack closer to fruition.  Alternately it may provide unauthorized access not directly related to the VoIP portion of the network.

High

A high severity issue can be exploited to compromise one or more nodes within the deployment but may require authentication, especially when exploiting multiple systems simultaneously. In addition, it may be possible to protect against untrusted exploitation of the issue by deploying traditional security tools.

Critical

A critical severity issue can be exploited by an untrusted individual to compromise the entire deployment under review.  There are no security or protective mechanisms in place that will mediate exploitation of this vulnerability by an untrusted individual.

Vendor Response Legend

Patch available
Workaround proposed
Attempting to address the issue
No vendor response
Copyright © VoIPshield Systems Inc. All rights reserved.