CVE-2011-3008
Estado: ModificadaMedia (5)—
The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as demonstrated by alarm and log information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.54%
- Percentil entre todas las CVEs puntuadas: 74
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-16
Referencias
- http://support.avaya.com/css/P8/documents/100140483
- http://www.kb.cert.org/vuls/id/690315
- http://www.securityfocus.com/bid/48942
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68922
- http://support.avaya.com/css/P8/documents/100140483
- http://www.kb.cert.org/vuls/id/690315
- http://www.securityfocus.com/bid/48942
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68922
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-3008",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-08-05T21:55:09.280",
"references": [
{
"url": "http://support.avaya.com/css/P8/documents/100140483",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/690315",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/48942",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/68922",
"source": "cve@mitre.org"
},
{
"url": "http://support.avaya.com/css/P8/documents/100140483",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/690315",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/48942",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/68922",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-16"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as demonstrated by alarm and log information."
},
{
"lang": "es",
"value": "La configuración por defecto del Avaya Secure Access Link (SAL) Gateway 1.5, 1.8 y 2.0 contiene determinados nombres de dominio en el campo URL del Secondary Core Server y del Secondary Remote Server, lo que permite a atacantes remotos obtener información confidencial utilizando accesos administrativos a esos dominios, como se ha demostrado con información de log y alarmas."
}
],
"lastModified": "2026-06-16T23:32:25.353",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:avaya:secure_access_link_gateway:1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF59FCAC-9DA2-46A8-ACD0-A3CFA497E475"
},
{
"criteria": "cpe:2.3:a:avaya:secure_access_link_gateway:1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6528966A-A33C-4AC0-8CD5-927BC19144E5"
},
{
"criteria": "cpe:2.3:a:avaya:secure_access_link_gateway:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98B73BC2-1881-4D12-AC61-DB666C556156"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}