PT-2019-19451 · Audiocodes · Audiocodes Mediant 800C-Msbr+1

Published

2019-07-19

·

Updated

2024-08-04

·

CVE-2019-9228

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AudioCodes Mediant 500L-MSBR versions F7.20A through 7.20A.252.062 AudioCodes Mediant 500-MBSR versions F7.20A through 7.20A.252.062 AudioCodes Mediant M800B-MSBR versions F7.20A through 7.20A.252.062 AudioCodes Mediant 800C-MSBR versions F7.20A through 7.20A.252.062
Description The management SSH and management TELNET features in the affected devices allow remote attackers to cause a denial of service via 5 unauthenticated connection attempts. This is because the maximum number of unauthenticated clients that can be configured is 5.
Recommendations For AudioCodes Mediant 500L-MSBR versions F7.20A through 7.20A.252.062, consider restricting access to the management SSH and TELNET features to prevent unauthenticated connection attempts. For AudioCodes Mediant 500-MBSR versions F7.20A through 7.20A.252.062, consider restricting access to the management SSH and TELNET features to prevent unauthenticated connection attempts. For AudioCodes Mediant M800B-MSBR versions F7.20A through 7.20A.252.062, consider restricting access to the management SSH and TELNET features to prevent unauthenticated connection attempts. For AudioCodes Mediant 800C-MSBR versions F7.20A through 7.20A.252.062, consider restricting access to the management SSH and TELNET features to prevent unauthenticated connection attempts.

Fix

Related Identifiers

CVE-2019-9228

Affected Products

Audiocodes Mediant 500L-Msbr
Audiocodes Mediant 800C-Msbr