CVE-2008-6797
Estado: ModificadaAlta (7.8)—
The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.70%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-6797",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-05-07T18:30:00.187",
"references": [
{
"url": "http://www.kb.cert.org/vuls/id/576996",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.mitel.com/resources/NuPoint_and_Exchange.pdf",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/34847",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/576996",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mitel.com/resources/NuPoint_and_Exchange.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/34847",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obtain sensitive information by sniffing the network."
},
{
"lang": "es",
"value": "El servidor en Mitel NuPoint Messenger R11 y R3 envía el nombre de usuario y contraseña en texto claro al servidor Exchange, lo que permite a los atacantes remotos obtener información sensibles rastreando la red."
}
],
"lastModified": "2026-06-16T23:02:59.700",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mitel:mitel_nupoint_messenger:r3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64EEFEF4-0274-4EB1-84CE-D0133742E163"
},
{
"criteria": "cpe:2.3:a:mitel:mitel_nupoint_messenger:r11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECE575AB-6AC1-41F0-8CD7-A7AC89CFFF9B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}