VYPR

SL1100

by NEC

CVEs (2)

  • CVE-2019-20029Jul 29, 2020
    risk 0.00cvss epss 0.02

    An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged…

  • CVE-2019-20027Jul 29, 2020
    risk 0.00cvss epss 0.01

    Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.