CVE-2019-20027: Critical severity nec sv8100 vulnerability
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-20027.
Which NEC PBXes are affected by this vulnerability?
Aspire-derived NEC PBXes including the SV8100, SV9100, SL1100, and SL2100 with software releases 7.0 or higher are affected.
What is the severity rating of CVE-2019-20027?
CVE-2019-20027 has a severity rating of 9.8 (Critical).
How can this vulnerability be exploited?
If incorrectly configured, this vulnerability allows a blank username and password combination to be entered as a valid, successfully authenticating account.
Where can I find more information about CVE-2019-20027?
You can find more information about CVE-2019-20027 at the following link: [https://shadytel.su/files/nec_cve.txt](https://shadytel.su/files/nec_cve.txt)