The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.
References
Configurations
History
No history.
Information
Published : 2008-08-25 21:41
Updated : 2024-02-28 11:21
NVD link : CVE-2008-3777
Mitre link : CVE-2008-3777
CVE.ORG link : CVE-2008-3777
JSON object : View
Products Affected
avaya
- communication_manager
- s8300c_server
- sip_enablement_services
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor