VYPR

SL1100

by NEC

CVEs (3)

  • CVE-2019-20029HigJul 29, 2020
    risk 0.57cvss 8.8epss 0.02

    An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged…

  • CVE-2019-20028HigJul 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.

  • CVE-2019-20032MedJul 29, 2020
    risk 0.42cvss 6.5epss 0.01

    An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices, may access the system's administration modem.