// For flags

CVE-2011-3008

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as demonstrated by alarm and log information.

La configuración por defecto del Avaya Secure Access Link (SAL) Gateway 1.5, 1.8 y 2.0 contiene determinados nombres de dominio en el campo URL del Secondary Core Server y del Secondary Remote Server, lo que permite a atacantes remotos obtener información confidencial utilizando accesos administrativos a esos dominios, como se ha demostrado con información de log y alarmas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-08-05 CVE Reserved
  • 2011-08-05 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-16: Configuration
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Avaya
Search vendor "Avaya"
Secure Access Link Gateway
Search vendor "Avaya" for product "Secure Access Link Gateway"
1.5
Search vendor "Avaya" for product "Secure Access Link Gateway" and version "1.5"
-
Affected
Avaya
Search vendor "Avaya"
Secure Access Link Gateway
Search vendor "Avaya" for product "Secure Access Link Gateway"
1.8
Search vendor "Avaya" for product "Secure Access Link Gateway" and version "1.8"
-
Affected
Avaya
Search vendor "Avaya"
Secure Access Link Gateway
Search vendor "Avaya" for product "Secure Access Link Gateway"
2.0
Search vendor "Avaya" for product "Secure Access Link Gateway" and version "2.0"
-
Affected