← Back

CVE-2019-9228

nvd nist
Published: Jul 19, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.

Affected (4)

4 products
Median 500l Msbr Firmware
Median 500 Msbr Firmware
Median M800b Msbr Firmware
Median 800c Msbr Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From f7.20a to f7.20a.252.062
Running on/withPlatform Versions
Audiocodes
Median 500l Msbr
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From f7.20a to f7.20a.252.062
Running on/withPlatform Versions
Audiocodes
Median 500 Msbr
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From f7.20a to f7.20a.252.062
Running on/withPlatform Versions
Audiocodes
Median M800b Msbr
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From f7.20a to f7.20a.252.062
Running on/withPlatform Versions
Audiocodes
Median 800c Msbr
All versions

Timeline

No history available yet.