Dialogic develops media server and communications platforms, with its vulnerability profile centered on the PowerMedia XMS product line. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through a durable cluster of credential-management, access-control, and input-handling weakness classes including insufficiently protected and hard-coded credentials, CSRF, link-following flaws, and SQL injection, reflecting both the authentication demands and the data-handling surface of a server-side communications system. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dialogic over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11641CRITICAL Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to | Jul 3, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-11635CRITICAL Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS thr | Jul 3, 2018 | 9.8 | 27 | NO | NO |
CVE-2018-11640CRITICAL XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (r | Jul 3, 2018 | 9.1 | 26 | NO | NO |
CVE-2018-11643HIGH SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterP | Jul 3, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-11636HIGH Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execute malicious and unauthorized a | Jul 3, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-11639HIGH Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows | Jul 3, 2018 | 8.1 | 23 | NO | NO |
CVE-2018-11634HIGH Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartex | Jul 3, 2018 | 7.8 | 23 | NO | NO |
CVE-2018-11642HIGH Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root | Jul 3, 2018 | 7.8 | 22 | NO | NO |
CVE-2018-11638HIGH Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to upload malicious code | Jul 3, 2018 | 7.2 | 22 | NO | NO |
CVE-2018-11637HIGH Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary files from the /var/ directory beca | Jul 3, 2018 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dialogic.
Media articles that mention a CVE ID that affects a product developed by Dialogic — matched by CVE ID, not by vendor name.