topleft topright
VoIPshield System stopped publishing new vulnerabilities as of November 2008. If you are interested in newest VoIP vulnerabilities please send an email to info@voipshield.com.

    

Use the Search field or Category and Vendor filters to navigate the database of vulnerabilities. Click vulnerability for details.

Severity Tracking ID Category Vendor Product Released Response
Microsoft Communicator Emoticon Denial of Service
3 VSRMS-2008-001 Denial of Service Microsoft Microsoft Communicator 2008-11-11 att_issue
Microsoft Communicator Real-time Transport Control Protocol Report Block Denial of Service
3 VSRMS-2008-002 Denial of Service Microsoft Microsoft Communicator 2008-11-11 att_issue
Microsoft Communicator INVITE Flood Denial of Service
3 VSRMS-2008-003 Denial of Service Microsoft Microsoft Communicator 2008-11-11 att_issue
Nortel Multimedia Communications Server 5100 Call Spoofing and Redirection
3 VSRNT-2008-010 Unauthorized Access Nortel Multimedia Communications Server 5100 3.x 2008-10-08 att_issue
Nortel Multimedia Communications Server 5100 IP Client Manager UNIStim File Transfer Protocol - Connection Details
3 VSRNT-2008-011 Denial of Service Nortel Multimedia Communications Server 5100 3.x 2008-10-08 att_issue
Avaya Communication Manager Web Administration Interface - Privilege Elevation Vulnerability
3 VSRAV-2008-007 Code Execution Avaya Communication Manager 4.x 2008-10-08 patch
Avaya Communication Manager Web Administration Interface - Code Execution Vulnerability
3 VSRAV-2008-007 Code Execution Avaya Communication Manager 4.x 2008-10-08 patch
Avaya Communication Manager Unauthorized Web Access
2 VSRAV-2008-008 Unauthorized Access Avaya Communication Manager 4.x 2008-10-08 att_issue
Avaya one-X Desktop Edition Session Initiation Protocol Denial of Service
3 VSRAV-2008-009 Denial of Service Avaya Avaya one-X Desktop Edition 2.1 2008-10-08 att_issue
Avaya IP Softphone H.323 Denial of Service
3 VSRAV-2008-010 Denial of Service Avaya Avaya IP Softphone 6.0 SP4 2008-10-08 att_issue
Cisco Unity Authentication Bypass
4 VSRCS-2008-008 Unauthorized Access Cisco Cisco Unity 7.0 2008-10-08 patch
Cisco Unity Stored Cross-Site Scripting Vulnerability
3 VSRCS-2008-009 Code Execution Cisco Cisco Unity 7.0 2008-10-08 att_issue
Cisco Unity Session Exhaustion Denial of Service
4 VSRCS-2008-010 Denial of Service Cisco Cisco Unity 7.0 2008-10-08 patch
Cisco Unity Multiple Denial of Service Vulnerabilities
4 VSRCS-2008-011 Denial of Service Cisco Cisco Unity 7.0, Other 2008-10-08 att_issue
Cisco Unity Reports Information Disclosure
2 VSRCS-2008-012 Unauthorized Access Cisco Cisco Unity 7.0 2008-10-08 patch
CS1000 Oversized Command DoS
4 VSRNT-2008-006 Denial of Service Nortel Communications Server 1000 4.50.x 2008-06-25 att_issue
Serviceability Monitoring Tool Unauthenticated Access to Phone Device Search Function
3 VSRCS-2008-006 Unauthorized Access Cisco Call Manager 4.x, Unified Communications Manager 5.x, Unified Communications Manager 6.x 2008-06-25 patch
Serviceability Monitoring Tool Unauthenticated Access to Server Processes Function
3 VSRCS-2008-006 Unauthorized Access Cisco Unified Communications Manager 5.x, Unified Communications Manager 6.x 2008-06-25 patch
SIP Enablement Service View/Restore Data Configuration Privilege Elevation
3 VSRAV-2008-004 Code Execution Avaya Communication Manager 3.1.x, Communication Manager 4.x 2008-06-25 att_issue
Communication Manager View/Restore Data Credential Privilege Elevation
3 VSRAV-2008-004 Code Execution Avaya Communication Manager 3.1.x 2008-06-25 att_issue
<< Start < Previous Next > End >>
Display # Results 1 - 20 of 97
 

Each line represents an individual vulnerability or group of vulnerabilities. For example, "UCM Multiple Hardcoded Passwords" is presented here in a single line but was reported to Nortel as sixteen (16) individual vulnerabilities.

Severity Legend

Click on a level for description
Low

A low severity issue falls into one of two categories.  Firstly, there are those that are not directly exploitable and affect a single IP client, a small subset of the deployment, or are quite innocuous taken by themselves. In other words, they provide information which either involves only a small number (or single) client and that information requires considerable other information or effort to be useful to an attacker.  The other category of low severity issues includes those that are best practices which are not intended to directly mitigate an exploitable risk but to increase overall security robustness and demonstrate due diligence.

Medium

A medium severity issue is typically an issue which can lead to further exploitation or provides short-lived effect on a minimal number of clients.  It may not be immediately exploitable but provides sufficient information or access to move an attack closer to fruition.  Alternately it may provide unauthorized access not directly related to the VoIP portion of the network.

High

A high severity issue can be exploited to compromise one or more nodes within the deployment but may require authentication, especially when exploiting multiple systems simultaneously. In addition, it may be possible to protect against untrusted exploitation of the issue by deploying traditional security tools.

Critical

A critical severity issue can be exploited by an untrusted individual to compromise the entire deployment under review.  There are no security or protective mechanisms in place that will mediate exploitation of this vulnerability by an untrusted individual.

Vendor Response Legend

Patch available
Workaround proposed
Attempting to address the issue
No vendor response
Copyright © VoIPshield Systems Inc. All rights reserved.