← Back

CVE-2008-3777

nvd nist
Published: Aug 25, 2008Modified: Apr 23, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.

Affected (2)

2 products
Sip Enablement Services
Communication Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 5.0
Running on/withPlatform Versions
Avaya
S8300c Server
All versions

References (6)

Timeline

No history available yet.