We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2019-20029



Assignermitre
Reserved2019-12-27
Published2020-07-29
Updated2024-08-05

Description

An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.

References

https://shadytel.su/files/nec_cve.txt

cve.org CVE-2019-20029

nvd.nist.gov CVE-2019-20029

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2019-20029
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.