« Volver al listado

CVE-2019-7006

Estado: ModificadaMedia (5.5)—

Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-7006",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "securityalerts@avaya.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 1
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "securityalerts@avaya.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-02-27T00:29:00.230",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/107175",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "securityalerts@avaya.com"
    },
    {
      "url": "https://downloads.avaya.com/css/P8/documents/101055601",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "securityalerts@avaya.com"
    },
    {
      "url": "https://downloads.avaya.com/css/P8/documents/101055661",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "securityalerts@avaya.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/107175",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://downloads.avaya.com/css/P8/documents/101055601",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://downloads.avaya.com/css/P8/documents/101055661",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-327"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13."
    },
    {
      "lang": "es",
      "value": "Avaya one-X Communicator utiliza algoritmos criptográficos débiles en el componente de autenticación del cliente que podría permitir a un atacante local descifrar información sensible. Las versiones afectadas incluyen todas las 6.2.x anteriores a la 6.2 SP13."
    }
  ],
  "lastModified": "2026-06-17T02:39:54.467",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBF4025F-35D2-4E9D-9C17-B9386D69E842"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:fp10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BABD5744-5840-470E-B32F-9739BCA134EC"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:fp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "225458CC-B46F-4C5B-948E-596003DE2F26"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:fp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60337789-49AA-48B6-B4F5-A38C63C0D76C"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:fp6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73633F3D-0DFD-4066-A809-B9B908002336"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA87C53D-D7AB-42A8-B0FB-4CA28D131572"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:sp12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA0D73A4-0B19-4C76-BAEF-1B454D88D0A7"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F912FD83-9FB1-4D56-BA85-CEAC94FDD324"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7784F4DB-7D12-4F92-8564-AD31426EF21F"
            },
            {
              "criteria": "cpe:2.3:a:avaya:one-x_communicator:6.2:sp7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F740A8F4-FC50-4125-B9C2-7531D0C0392E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "securityalerts@avaya.com"
}