Vulnerabilities > NEC > Sl1100 Firmware

DATE CVE VULNERABILITY TITLE RISK
2020-07-29 CVE-2019-20032 Unspecified vulnerability in NEC products
An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices, may access the system's administration modem.
network
low complexity
nec
4.0
2020-07-29 CVE-2019-20029 Improper Privilege Management vulnerability in NEC products
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices.
network
low complexity
nec CWE-269
6.5
2020-07-29 CVE-2019-20028 Information Exposure vulnerability in NEC products
Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.
network
low complexity
nec CWE-200
5.0
2020-07-29 CVE-2019-20027 Improper Authentication vulnerability in NEC products
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.
network
low complexity
nec CWE-287
7.5