CVE-2008-3778: High severity avaya aura sip enablement services vulnerability
The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, proceeds with Core router updates even when a login is invalid, which allows remote attackers to cause a denial of service (messaging outage) or gain privileges via an update request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3778?
CVE-2008-3778 has a high severity rating as it allows remote attackers to cause denial of service by exploiting the remote management interface.
How do I fix CVE-2008-3778?
To fix CVE-2008-3778, apply the latest security patches provided by Avaya for SIP Enablement Services version 5.0 and Communication Manager version 5.0.
What impact does CVE-2008-3778 have on affected systems?
CVE-2008-3778 can result in service disruptions as the vulnerability allows unauthorized access that can lead to denial of service.
Which versions are affected by CVE-2008-3778?
CVE-2008-3778 affects Avaya SIP Enablement Services 5.0 and Avaya Communication Manager 5.0.
Can CVE-2008-3778 be exploited remotely?
Yes, CVE-2008-3778 can be exploited remotely due to the flaws in the remote management interface.