CVE-2021-20677
3.1
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Exploitability: 1.6 / Impact: 1.4
Source: NVD
Description
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.00 to 3.51 |
| Running on/with | Platform Versions |
|---|---|
Necplatforms Univerge Aspire Wx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.00 to 9.70 |
| Running on/with | Platform Versions |
|---|---|
Necplatforms Univerge Aspire Ux | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.00 to 10.70 |
| Running on/with | Platform Versions |
|---|---|
Necplatforms Univerge Sv9100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.00 to 3.00 |
| Running on/with | Platform Versions |
|---|---|
Necplatforms Sl2100 | All versions |
References (4)
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.