// For flags

CVE-2019-7006

Avaya one-X Communicator Weak Encryption

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13.

Avaya one-X Communicator utiliza algoritmos criptográficos débiles en el componente de autenticación del cliente que podría permitir a un atacante local descifrar información sensible. Las versiones afectadas incluyen todas las 6.2.x anteriores a la 6.2 SP13.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-28 CVE Reserved
  • 2019-02-27 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
-
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
fp10
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
fp3
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
fp4
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
fp6
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
sp1
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
sp12
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
sp2
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
sp5
Affected
Avaya
Search vendor "Avaya"
One-x Communicator
Search vendor "Avaya" for product "One-x Communicator"
6.2
Search vendor "Avaya" for product "One-x Communicator" and version "6.2"
sp7
Affected