Show plain JSON{"id": "CVE-2019-20031", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.4, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.1, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.2, "exploitabilityScore": 3.9}]}, "published": "2020-07-29T18:15:13.750", "references": [{"url": "https://shadytel.su/files/nec_cve.txt", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://shadytel.su/files/nec_cve.txt", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-307"}]}], "descriptions": [{"lang": "en", "value": "NEC UM8000, UM4730 and prior non-InMail voicemail systems with all known software versions may permit an infinite number of login attempts in the telephone user interface (TUI), effectively allowing brute force attacks."}, {"lang": "es", "value": "NEC UM8000, UM4730 y anteriores a sistemas de correo de voz que no son InMail con todas las versiones de software conocidas pueden permitir un n\u00famero infinito de intentos de inicio de sesi\u00f3n en la interfaz de usuario del tel\u00e9fono (TUI), permitiendo efectivamente ataques de fuerza bruta"}], "lastModified": "2024-11-21T04:37:56.053", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:nec:um8000_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2A1D915-BEBE-4C38-9362-CD42D368E376"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:nec:um8000:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AB18A6B9-5C17-4DB1-80B0-C6E1AE055F64"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:nec:um4730_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96416DC6-6703-410F-A3CD-42FD8380A467"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:nec:um4730:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7E46D04F-C640-4409-82C2-6DB094227038"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org"}