Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.
2020-07-29T18:15:13.327
2024-11-21T04:37:55.407
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nec | sv8100_firmware | ≥ 7.0 | Yes |
Hardware | nec | sv8100 | - | No |
Operating System | nec | sv9100_firmware | ≥ 7.0 | Yes |
Hardware | nec | sv9100 | - | No |
Operating System | nec | sl1100_firmware | ≥ 7.0 | Yes |
Hardware | nec | sl1100 | - | No |
Operating System | nec | sl2100_firmware | ≥ 7.0 | Yes |
Hardware | nec | sl2100 | - | No |