Vulnerabilities > Nortel > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-04-01 CVE-2008-6578 Multiple Security vulnerability in Nortel Cs1000 4.50
Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitrary commands to gain privileges, obtain sensitive information, or cause a denial of service via unknown vectors.
network
low complexity
nortel
critical
10.0
2009-04-01 CVE-2008-6577 Credentials Management vulnerability in Nortel Cs1000 4.50
Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspecified hard-coded accounts and passwords, which allows remote attackers to gain privileges.
network
low complexity
nortel CWE-255
critical
10.0
2007-04-27 CVE-2007-2333 Remote Unauthorized Access vulnerability in Nortel Contivity, VPN Router 5000 and VPN Router Portfolio
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.
network
low complexity
nortel
critical
10.0
2007-04-27 CVE-2007-2332 Remote Unauthorized Access vulnerability in Nortel VPN Routers
Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.
network
low complexity
nortel
critical
9.0
2007-04-02 CVE-2007-1820 Remote Security vulnerability in Meridian Mail
Nortel Networks CallPilot and Meridian Mail voicemail systems, when a mailbox has auto logon enabled, allow remote attackers to retrieve or remove messages, or reconfigure the mailbox, by spoofing Calling Number Identification (CNID, aka Caller ID).
network
nortel
critical
9.3
2006-12-20 CVE-2006-6670 Unspecified vulnerability in Nortel Callpilot Server 4.X
Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL.
network
low complexity
nortel
critical
10.0