CVE-2008-3777: Infoleak
The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2008-3777?
CVE-2008-3777 is a security vulnerability in Avaya SIP Enablement Services 5.0 that exposes account names and passwords in system logs during failed login attempts.
What is the severity of CVE-2008-3777?
CVE-2008-3777 is considered to have a moderate severity due to potential exposure of sensitive login credentials.
How do I fix CVE-2008-3777?
To fix CVE-2008-3777, it is recommended to upgrade to a patched version of Avaya SIP Enablement Services or Communication Manager that does not log sensitive information.
Who is affected by CVE-2008-3777?
CVE-2008-3777 affects users of Avaya SIP Enablement Services 5.0 and Communication Manager 5.0 on the S8300C server configuration.
What are the risks associated with CVE-2008-3777?
The risks associated with CVE-2008-3777 include unauthorized access to sensitive account login information by local users, increasing the likelihood of credential compromise.