PT-2020-10325 · Nec · Sv9100+5
Published
2020-07-29
·
Updated
2020-08-03
·
CVE-2019-20032
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
NEC PBXes versions of SV8100, SV9100, SL1100, and SL2100
Description
An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes may access the system's administration modem.
Recommendations
For all versions of SV8100, SV9100, SL1100, and SL2100 devices, consider restricting access to the InMail voicemail box and the find me/follow me feature until a patch is available.
As a temporary workaround, consider disabling the find me/follow me feature on the affected devices to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aspire
Winmail
Sl1100
Sl2100
Sv8100
Sv9100