Communication Manager

Vendor:

First CVE: Feb 3, 2004 · Active for 22 years

16
Total CVEs
More Total CVEs than 92% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Communication Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2004
22 years ago
Most Recent CVE
Apr 10, 2009
6,317 days ago

CVE Severity & Scoring

Communication Manager16 CVEs
All CVEs352,727 CVEs
LowMediumHigh
Attack Vector
Local1 (6.3%)
Network0 (0.0%)
Unknown15 (93.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (6.3%)
High0 (0.0%)
Unknown15 (93.8%)
User Interaction
None1 (6.3%)
Unknown15 (93.8%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None0 (0.0%)
Unknown15 (93.8%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users
Apr 10, 20099.023NONO
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated admini
Apr 10, 20099.023NONO
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenti
Apr 10, 20099.023NONO
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote
Apr 10, 20099.023NONO
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow re
Dec 24, 20089.023NONO
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vec
Jul 9, 20087.822NONO
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
Feb 3, 20047.522NONO
Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remot
Apr 10, 20097.820NONO
Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges and cause a denial of service via
Apr 1, 20097.519NONO
The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, pro
Aug 25, 20087.519NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Communication Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.1.215.01.4%00
5.1.115.01.4%00
5.115.01.4%00
5.056.31.9%00
4.0.377.92.0%00
4.0.219.02.1%00
4.0.168.42.1%00
4.078.22.0%00
3.1.587.21.7%00
3.1.4107.41.8%00
3.1.3117.82.0%00
3.1.2117.82.0%00
3.1.1117.82.0%00
3.197.71.9%00
2.0.117.57.6%00
2.017.57.6%00
1.3.117.57.6%00
1.117.57.6%00