CVE-2019-20031

NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks.
References
Link Resource
https://shadytel.su/files/nec_cve.txt Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nec:um8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nec:um8000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nec:um4730_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nec:um4730:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-07-29 18:15

Updated : 2023-12-10 13:27


NVD link : CVE-2019-20031

Mitre link : CVE-2019-20031

CVE.ORG link : CVE-2019-20031


JSON object : View

Products Affected

nec

  • um8000_firmware
  • um4730
  • um4730_firmware
  • um8000
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts