CVE-2003-20001: Infoleak
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-20001?
CVE-2003-20001 is considered a moderate severity vulnerability due to the unauthorized disclosure of information.
How do I fix CVE-2003-20001?
To fix CVE-2003-20001, ensure that TELNET access is disabled on the Mitel ICP VoIP 3100 devices.
What type of information is disclosed by CVE-2003-20001?
CVE-2003-20001 discloses details about incoming calls and SMDR records during a specific login process.
What devices are affected by CVE-2003-20001?
CVE-2003-20001 affects Mitel ICP VoIP 3100 devices.
Is CVE-2003-20001 a remote or local vulnerability?
CVE-2003-20001 is a remote vulnerability, allowing external users to exploit it over the network.