Vulnerabilities > CVE-2002-0674 - Unspecified vulnerability in Pingtel Xpressa 1.2.5/1.2.7.4

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
pingtel

Summary

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication.

Vulnerable Configurations

Part Description Count
Hardware
Pingtel
2