Vulnerabilities > Avaya > Communication Manager > 4.0.1

DATE CVE VULNERABILITY TITLE RISK
2009-04-10 CVE-2008-6711 Multiple Security vulnerability in Avaya Communication Manager
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrary commands via unknown vectors related to "viewing system logs."
network
low complexity
avaya
critical
9.0
2009-04-10 CVE-2008-6710 Multiple Security vulnerability in Avaya Communication Manager
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain root privileges via unknown vectors related to "configuring data viewing or restoring credentials."
network
low complexity
avaya
critical
9.0
2009-04-10 CVE-2008-6708 Multiple Security vulnerability in Avaya Communication Manager and SIP Enablement Services
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote authenticated administrators to gain root privileges via unknown vectors related to configuration of "data viewing or restoring parameters."
network
low complexity
avaya
critical
9.0
2009-04-01 CVE-2008-6575 Unspecified vulnerability in Avaya Communication Manager
Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated users to cause a denial of service (resource consumption) via unknown vectors.
network
low complexity
avaya
6.8
2009-04-01 CVE-2008-6574 Input Validation vulnerability in Avaya SIP Enablement Services (SES) Server
Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges and cause a denial of service via unknown vectors related to reuse of valid credentials.
network
low complexity
avaya
7.5
2008-12-24 CVE-2008-5709 Improper Input Validation vulnerability in Avaya Communication Manager
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow remote authenticated users to execute arbitrary code via unknown attack vectors in the (1) Set Static Routes and (2) Backup History components.
network
low complexity
avaya CWE-20
critical
9.0