MEDIUM · 5.0

CVE-2005-0506

The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames an...

Vulnerability Description

The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AvayaIp Office Phone ManagerAll versions
AvayaIp Soft PhoneAll versions

References

FAQ

What is CVE-2005-0506?

CVE-2005-0506 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames an...

How severe is CVE-2005-0506?

CVE-2005-0506 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0506?

Check the references section above for vendor advisories and patch information. Affected products include: Avaya Ip Office Phone Manager, Avaya Ip Soft Phone.