CVE-2019-20033: Critical severity nec sv8100 vulnerability
On Aspire-derived NEC PBXes, including all versions of SV8100 devices, a set of documented, static login credentials may be used to access the DIM interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20033?
CVE-2019-20033 is a vulnerability found in Aspire-derived NEC PBXes, including all versions of SV8100 devices. Static login credentials can be used to access the DIM interface.
What is the severity of CVE-2019-20033?
The severity of CVE-2019-20033 is critical with a CVSS score of 9.8.
How can I fix CVE-2019-20033?
To fix CVE-2019-20033, it is recommended to update the firmware on Aspire-derived NEC PBXes, specifically the SV8100 devices.
What software is affected by CVE-2019-20033?
The NEC SV8100 firmware in all versions is affected by CVE-2019-20033.
Is NEC SV8100 vulnerable to CVE-2019-20033?
No, NEC SV8100 devices are not vulnerable to CVE-2019-20033.
Can I use the documented static login credentials to access the DIM interface on NEC PBXes?
Yes, the vulnerability allows the use of documented static login credentials to access the DIM interface on Aspire-derived NEC PBXes, including all versions of SV8100 devices.
What is the CWE of CVE-2019-20033?
The CWE of CVE-2019-20033 is CWE-287.
Are there any references for CVE-2019-20033?
Yes, you can find more information about CVE-2019-20033 at the following reference: https://shadytel.su/files/nec_cve.txt