Vulnerabilities > Nortel > High

DATE CVE VULNERABILITY TITLE RISK
2005-08-16 CVE-2005-2579 Local Security vulnerability in Nortel Contivity V0501.030
Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a program with the File Open dialog box.
local
low complexity
nortel
7.2
2004-02-17 CVE-2004-0056 Unspecified vulnerability in Nortel products
Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
network
low complexity
nortel
7.5
2003-12-31 CVE-2003-1115 Unspecified vulnerability in Nortel Succession Communication Server 2000
The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
network
low complexity
nortel
7.5
2002-07-03 CVE-2002-0540 Unspecified vulnerability in Nortel CVX 1800 Multi-Service Access Switch 3.6.3
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.
network
low complexity
nortel
7.5
1999-12-29 CVE-2000-0009 Unspecified vulnerability in Nortel Optivity NET Architect 2.0
The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.
local
low complexity
nortel
7.2