First published: Fri Mar 26 2021(Updated: )
UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Necplatforms Univerge Aspire Wx | >=1.00<=3.51 | |
Necplatforms Univerge Aspire Wx Firmware | ||
Necplatforms Univerge Aspire Ux Firmware | >=1.00<=9.70 | |
Necplatforms Univerge Aspire Ux Firmware | ||
Necplatforms Univerge Sv9100 | >=1.00<=10.70 | |
NEC Univerge Sv9100 WebPro | ||
NEC Platforms SL2100 | >=1.00<=3.00 | |
NEC SL2100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20677 is classified as a high-severity vulnerability due to its potential to cause a denial of service condition.
To mitigate CVE-2021-20677, users should upgrade their UNIVERGE Aspire series PBX to the latest secure firmware version.
CVE-2021-20677 affects UNIVERGE Aspire WX, Aspire UX, SV9100, and SL2100 systems running specific firmware versions.
CVE-2021-20677 is a remote authenticated denial of service vulnerability.
Yes, CVE-2021-20677 can be exploited by remote authenticated attackers.