CVE-2019-9228
Published Jul 19, 2019
Last updated 3 months ago
Overview
- Description
- An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.
- Source
- cve@mitre.org
- NVD status
- Modified
- CNA Tags
- disputed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:audiocodes:median_500l-msbr_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9C0A971-224A-4557-806E-1F6AED9BEC85", "versionEndIncluding": "f7.20a.252.062", "versionStartIncluding": "f7.20a" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:audiocodes:median_500l-msbr:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1228A9BF-1C20-49A9-917A-20804AF739CB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:audiocodes:median_500-msbr_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1998072-F31C-4C4A-A3DB-758714E4675F", "versionEndIncluding": "f7.20a.252.062", "versionStartIncluding": "f7.20a" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:audiocodes:median_500-msbr:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9B7B3CB2-907E-40B8-A5A4-363F6B49B3EC" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:audiocodes:median_m800b-msbr_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46C56E15-F140-419A-BE54-D24507CF9D1A", "versionEndIncluding": "f7.20a.252.062", "versionStartIncluding": "f7.20a" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:audiocodes:median_m800b-msbr:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CC2AEC67-FEE5-42A8-AB33-908FD4492BE3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:audiocodes:median_800c-msbr_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33D9E844-7055-474A-9B83-0AD04015B03A", "versionEndIncluding": "f7.20a.252.062", "versionStartIncluding": "f7.20a" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:audiocodes:median_800c-msbr:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "60642B30-DE57-4630-8236-05E71B785571" } ], "operator": "OR" } ], "operator": "AND" } ]