CVE-2008-6706
Estado: ModificadaAlta (7.8)—
Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system utility that decrypts "subscriber table passwords," (4) a system utility that decrypts database passwords, and (5) a system utility that encrypts "subscriber table passwords."
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.26%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-noinfo
Referencias
- http://osvdb.org/46602
- http://secunia.com/advisories/30751
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htm
- http://www.securityfocus.com/bid/29939
- http://www.voipshield.com/research-details.php?id=81
- http://www.voipshield.com/research-details.php?id=82
- http://www.voipshield.com/research-details.php?id=83
- http://www.voipshield.com/research-details.php?id=84
- http://www.voipshield.com/research-details.php?id=85
- http://www.vupen.com/english/advisories/2008/1943/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43382
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43383
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43387
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43388
- http://osvdb.org/46602
- http://secunia.com/advisories/30751
- http://support.avaya.com/elmodocs2/security/ASA-2008-268.htm
- http://www.securityfocus.com/bid/29939
- http://www.voipshield.com/research-details.php?id=81
- http://www.voipshield.com/research-details.php?id=82
- http://www.voipshield.com/research-details.php?id=83
- http://www.voipshield.com/research-details.php?id=84
- http://www.voipshield.com/research-details.php?id=85
- http://www.vupen.com/english/advisories/2008/1943/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43382
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43383
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43387
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43388
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-6706",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-04-10T22:00:00.640",
"references": [
{
"url": "http://osvdb.org/46602",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/30751",
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-268.htm",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/29939",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=81",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=82",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=83",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=84",
"source": "cve@mitre.org"
},
{
"url": "http://www.voipshield.com/research-details.php?id=85",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1943/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43382",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43383",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43387",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43388",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/46602",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/30751",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.avaya.com/elmodocs2/security/ASA-2008-268.htm",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/29939",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=81",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=82",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=83",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=84",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.voipshield.com/research-details.php?id=85",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1943/references",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43382",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43383",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43387",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43388",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system utility that decrypts \"subscriber table passwords,\" (4) a system utility that decrypts database passwords, and (5) a system utility that encrypts \"subscriber table passwords.\""
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades no especificadas en el interfase de gestión web en Avaya SIP Enablement Services (SES) v3.x y v4.0, como los usados en Avaya Communicatión Manager v3.1.x, permite a atacantes remotos conseguir (1)configuración de la aplicación del servidor, (2) configuración del servidor de bases de datos, incluidas claves cifradas, (3) utilidad del sistema que desencripta \"claves de tablas de suscriptor\", (4) utilidad del sistema que desencripta las claves de la base de datos, y (5) una utilidad del sistema que encripta \"claves de tablas de suscriptor\"."
}
],
"lastModified": "2026-06-16T23:02:48.730",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:avaya:sip_enablement_services:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8D4881F-650A-4FA1-B604-70EBBED41AE7"
},
{
"criteria": "cpe:2.3:a:avaya:sip_enablement_services:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9EB9ECB-9ABF-40ED-9116-D3FE9FC73B38"
},
{
"criteria": "cpe:2.3:a:avaya:sip_enablement_services:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43F41650-7E55-436A-9935-8CE88B428680"
},
{
"criteria": "cpe:2.3:a:avaya:sip_enablement_services:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BFF25B3-B7C7-479C-8C2A-995E568C3395"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88F5C363-3A38-43FC-A06D-73E280AB844B"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4030E5D-BC15-481D-A15E-98FAE65130D9"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3FC3A86-CE3D-4C12-9E31-7F7280EF9D28"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BBD119B9-FE11-4165-943D-119E906DC013"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89F99C5C-C184-4A5C-B8BA-F558C4A38730"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.4:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1EAA2BC9-4794-4441-8AA8-3C1B7297FD06"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.4:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "423E4EEB-3D6F-449E-B623-C8D051E8FA3B"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87089C0E-2241-46A7-93EE-EC41D52A89C6"
},
{
"criteria": "cpe:2.3:a:avaya:communication_manager:3.1.5:sp0:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BD89D61-0B42-4DDE-99F1-71570A37A136"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}