[Japanese] | |
JVNDB-2021-000110 | |
UNIVERGE DT Series vulnerable to missing encryption of sensitive data | |
Overview | |
UNIVERGE IP Phone DT Series and PC tools for DT Series maintainers (IP Phone Manager and Data Maintenance Tool) provided by NEC Platforms, Ltd. contain a missing encryption vulnerability (CWE-311). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 3.1 (Low) [IPA Score]
CVSS V2 Severity:
Base Metrics 1.8 (Low) [IPA Score]
| |
Affected Products | |
| |
NEC Platforms, Ltd. | |
| |
Impact | |
If a remote attacker who can access to the internal network setting the product analyzes packets while using the IP Phone Manager or Data Maintenance Tool, the phone configuration information may be obtained. Furthermore, the obtained configuration information may be abused to alter the phone configuration information, which may lead to the IP Phones unusable. | |
Solution | |
[Update the Software] | |
Vendor Information | |
NEC Platforms, Ltd. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2021/12/17 |
Date First Published | 2021/12/17 |
Date Last Updated | 2021/12/17 |