PT-2020-10325 · Nec · Sv9100+5

Published

2020-07-29

·

Updated

2020-08-03

·

CVE-2019-20032

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions NEC PBXes versions of SV8100, SV9100, SL1100, and SL2100
Description An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes may access the system's administration modem.
Recommendations For all versions of SV8100, SV9100, SL1100, and SL2100 devices, consider restricting access to the InMail voicemail box and the find me/follow me feature until a patch is available. As a temporary workaround, consider disabling the find me/follow me feature on the affected devices to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-20032

Affected Products

Aspire
Winmail
Sl1100
Sl2100
Sv8100
Sv9100