pingtel records
12 published records for vendor pingtel.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2002-0667No exploit | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attapingtel · xpressa | Critical10.0 | — | 2.6% | Jul 23, 2002 |
39Monitor | CVE-2002-0671No exploit | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the intepingtel · xpressa firmware · CWE-494 | Critical9.8 | — | 1.2% | Jul 23, 2002 |
30Monitor | CVE-2002-0670No exploit | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTpingtel · xpressa | High7.5 | — | 1.6% | Jul 23, 2002 |
30Monitor | CVE-2002-0668No exploit | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwpingtel · xpressa | High7.5 | — | 1.3% | Jul 23, 2002 |
28Monitor | CVE-2002-0674No exploit | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allowpingtel · xpressa | High7.2 | — | 0.4% | Jul 23, 2002 |
21Monitor | CVE-2004-1680No exploit | application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (Vxpingtel · xpressa | Medium5.0 | — | 1.9% | Sep 13, 2004 |
20Monitor | CVE-2002-1935No exploit | Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identificatipingtel · xpressa | Medium5.0 | — | 1.4% | Dec 31, 2002 |
20Monitor | CVE-2002-1934No exploit | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtapingtel · xpressa | Medium5.0 | — | 1.2% | Dec 31, 2002 |
20Monitor | CVE-2002-0669No exploit | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of servicepingtel · xpressa | Medium5.0 | — | 1.1% | Feb 19, 2003 |
18Monitor | CVE-2002-0672No exploit | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory depingtel · xpressa | Medium4.6 | — | 0.4% | Jul 23, 2002 |
18Monitor | CVE-2002-0675No exploit | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgradepingtel · xpressa | Medium4.6 | — | 0.4% | Jul 23, 2002 |
18Monitor | CVE-2002-0673No exploit | The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the pingtel · xpressa | Medium4.6 | — | 0.3% | Jul 23, 2002 |
- CVE-2002-066741Plan
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote atta
CriticalCVSS 10.0No exploitEPSS 3%pingtel · xpressaJul 23, 2002
- CVE-2002-067139Monitor
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the inte
CriticalCVSS 9.8No exploitEPSS 1%pingtel · xpressa firmwareJul 23, 2002
- CVE-2002-067030Monitor
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HT
HighCVSS 7.5No exploitEPSS 2%pingtel · xpressaJul 23, 2002
- CVE-2002-066830Monitor
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forw
HighCVSS 7.5No exploitEPSS 1%pingtel · xpressaJul 23, 2002
- CVE-2002-067428Monitor
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow
HighCVSS 7.2No exploitEPSS 0%pingtel · xpressaJul 23, 2002
- CVE-2004-168021Monitor
application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (Vx
MediumCVSS 5.0No exploitEPSS 2%pingtel · xpressaSep 13, 2004
- CVE-2002-193520Monitor
Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identificati
MediumCVSS 5.0No exploitEPSS 1%pingtel · xpressaDec 31, 2002
- CVE-2002-193420Monitor
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obta
MediumCVSS 5.0No exploitEPSS 1%pingtel · xpressaDec 31, 2002
- CVE-2002-066920Monitor
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service
MediumCVSS 5.0No exploitEPSS 1%pingtel · xpressaFeb 19, 2003
- CVE-2002-067218Monitor
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory de
MediumCVSS 4.6No exploitEPSS 0%pingtel · xpressaJul 23, 2002
- CVE-2002-067518Monitor
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade
MediumCVSS 4.6No exploitEPSS 0%pingtel · xpressaJul 23, 2002
- CVE-2002-067318Monitor
The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the
MediumCVSS 4.6No exploitEPSS 0%pingtel · xpressaJul 23, 2002