CVE-2019-20031

NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks.
References
Link Resource
https://shadytel.su/files/nec_cve.txt Third Party Advisory
https://shadytel.su/files/nec_cve.txt Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nec:um8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nec:um8000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nec:um4730_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nec:um4730:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:37

Type Values Removed Values Added
References () https://shadytel.su/files/nec_cve.txt - Third Party Advisory () https://shadytel.su/files/nec_cve.txt - Third Party Advisory

Information

Published : 2020-07-29 18:15

Updated : 2024-11-21 04:37


NVD link : CVE-2019-20031

Mitre link : CVE-2019-20031

CVE.ORG link : CVE-2019-20031


JSON object : View

Products Affected

nec

  • um8000
  • um4730
  • um4730_firmware
  • um8000_firmware
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts