PT-2005-1560 · Avaya · Avaya Ip Office Phone Manager
Grutz
·
Published
2005-02-22
·
Updated
2016-10-18
·
CVE-2005-0506
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Avaya IP Office Phone Manager (affected versions not specified)
Description
The issue allows local and possibly remote users to steal usernames and passwords, and impersonate other users, by accessing sensitive data stored in cleartext in a registry key. The vulnerable registry key is related to AvayaIP400Generic.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avaya Ip Office Phone Manager