VYPR
Unrated severityNVD Advisory· Published Jul 23, 2002· Updated Jun 16, 2026

CVE-2002-0674

CVE-2002-0674

Description

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication.

Affected products

3
  • Pingtel/Xpressa3 versions
    cpe:2.3:h:pingtel:xpressa:1.2.5:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:h:pingtel:xpressa:1.2.5:*:*:*:*:*:*:*
    • cpe:2.3:h:pingtel:xpressa:1.2.7.4:*:*:*:*:*:*:*
    • (no CPE)range: 1.2.5 to 1.2.7.4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.