NEC
NEC Um8000 Firmware: vulnerabilities and CVEs
NEC Um8000 Firmware has 2 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs2
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20031 | Critical (9.1) | 1.00% | — | Jul 29, 2020 | NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks. |
| CVE-2019-20030 | High (7.8) | 0.33% | — | Jul 29, 2020 | An attacker with knowledge of the modem access number on a NEC UM8000 voicemail system may use SSH tunneling or standard Linux utilities to gain access to the system's LAN port. All versions are affected. |
Other products by NEC
Expresscluster X · 19Aterm W300p Firmware · 18Expresscluster X Singleserversafe · 17Aterm Wg1200hp Firmware · 17Aterm Wg1800hp2 Firmware · 16Aterm Wr8170n Firmware · 16Aterm Wr8175n Firmware · 16Aterm Wf300hp Firmware · 16Aterm Wg2200hp Firmware · 16Aterm Wg1800hp Firmware · 16Aterm Wg1400hp Firmware · 16Aterm Wg300hp Firmware · 16