CVE-2011-3008
Summary
| CVE | CVE-2011-3008 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-08-05 21:55:09 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server URL fields, which allows remote attackers to obtain sensitive information by leveraging administrative access to these domain names, as demonstrated by alarm and log information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Avaya | Secure Access Link Gateway | 1.5 | All | All | All |
| Application | Avaya | Secure Access Link Gateway | 1.8 | All | All | All |
| Application | Avaya | Secure Access Link Gateway | 2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| support.avaya.com/css/P8/documents/100140483 | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | Vendor Advisory |
| Avaya Secure Access Link (SAL) Gateway Invalid Domian Servers Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| US-CERT Vulnerability Note VU#690315 - Avaya Secure Access Link (SAL) Gateway information disclosure vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.