CVE-2019-7006

Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
avayaCNA
6.5 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
avayaone-x_communicator
6.2
avayaone-x_communicator
6.2:fp10
avayaone-x_communicator
6.2:fp3
avayaone-x_communicator
6.2:fp4
avayaone-x_communicator
6.2:fp6
avayaone-x_communicator
6.2:sp1
avayaone-x_communicator
6.2:sp12
avayaone-x_communicator
6.2:sp2
avayaone-x_communicator
6.2:sp5
avayaone-x_communicator
6.2:sp7
𝑥
= Vulnerable software versions