HIGH · 7.5

CVE-2019-9228

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management T...

Vulnerability Description

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
AudiocodesMedian 500L-Msbr Firmware>= f7.20a, <= f7.20a.252.062
AudiocodesMedian 500L-Msbr-
AudiocodesMedian 500-Msbr Firmware>= f7.20a, <= f7.20a.252.062
AudiocodesMedian 500-Msbr-
AudiocodesMedian M800B-Msbr Firmware>= f7.20a, <= f7.20a.252.062
AudiocodesMedian M800B-Msbr-
AudiocodesMedian 800C-Msbr Firmware>= f7.20a, <= f7.20a.252.062
AudiocodesMedian 800C-Msbr-

References

FAQ

What is CVE-2019-9228?

CVE-2019-9228 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management T...

How severe is CVE-2019-9228?

CVE-2019-9228 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-9228?

Check the references section above for vendor advisories and patch information. Affected products include: Audiocodes Median 500L-Msbr Firmware, Audiocodes Median 500L-Msbr, Audiocodes Median 500-Msbr Firmware, Audiocodes Median 500-Msbr, Audiocodes Median M800B-Msbr Firmware.