CVE-2019-20032: Medium severity nec sv8100 vulnerability
Published Jul 29, 2020
·Updated
An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices, may access the system's administration modem.
Affected Software
8 affected components
NEC Sv8100 Firmware
NEC SV8100
NEC Sv9100 Firmware
NEC SV9100
NEC Sl1100 Firmware
NEC SL1100
NEC Sl2100 Firmware
NEC SL2100
Event History
Jul 29, 2020
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
Description
Frequently Asked Questions
1
What is CVE-2019-20032?
CVE-2019-20032 is a vulnerability that allows an attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes to access the system's administration modem.
2
Which software versions are affected by CVE-2019-20032?
All versions of SV8100, SV9100, SL1100, and SL2100 devices are affected by CVE-2019-20032.
3
What is the severity of CVE-2019-20032?
CVE-2019-20032 has a severity score of 6.5, which is considered medium.
4
How can I fix CVE-2019-20032?
To fix CVE-2019-20032, it is recommended to update the firmware of the affected NEC PBX devices to a patched version.