CVE-2008-5709

Severity
9.0CRITICAL
EPSS
4.7%
top 10.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Latest updateMay 17

Description

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow remote authenticated users to execute arbitrary code via unknown attack vectors in the (1) Set Static Routes and (2) Backup History components.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages1 packages

NVDavaya/communication_manager8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-8xmm-h97j-gr2m: Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 32022-05-17
CVEList
CVE-2008-5709: Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 32008-12-24

💥Exploits & PoCs

1
Exploit-DB
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)2008-06-06