Skip to content
Noroxi

pingtel records

12 published records for vendor pingtel.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    12 records
    • Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote atta

      CriticalCVSS 10.0No exploitEPSS 3%

      pingtel · xpressaJul 23, 2002

    • CVE-2002-0671
      39Monitor

      Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the inte

      CriticalCVSS 9.8No exploitEPSS 1%

      pingtel · xpressa firmwareJul 23, 2002

    • CVE-2002-0670
      30Monitor

      The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HT

      HighCVSS 7.5No exploitEPSS 2%

      pingtel · xpressaJul 23, 2002

    • CVE-2002-0668
      30Monitor

      The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forw

      HighCVSS 7.5No exploitEPSS 1%

      pingtel · xpressaJul 23, 2002

    • CVE-2002-0674
      28Monitor

      Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow

      HighCVSS 7.2No exploitEPSS 0%

      pingtel · xpressaJul 23, 2002

    • CVE-2004-1680
      21Monitor

      application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (Vx

      MediumCVSS 5.0No exploitEPSS 2%

      pingtel · xpressaSep 13, 2004

    • CVE-2002-1935
      20Monitor

      Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identificati

      MediumCVSS 5.0No exploitEPSS 1%

      pingtel · xpressaDec 31, 2002

    • CVE-2002-1934
      20Monitor

      Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obta

      MediumCVSS 5.0No exploitEPSS 1%

      pingtel · xpressaDec 31, 2002

    • CVE-2002-0669
      20Monitor

      The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service

      MediumCVSS 5.0No exploitEPSS 1%

      pingtel · xpressaFeb 19, 2003

    • CVE-2002-0672
      18Monitor

      Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory de

      MediumCVSS 4.6No exploitEPSS 0%

      pingtel · xpressaJul 23, 2002

    • CVE-2002-0675
      18Monitor

      Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade

      MediumCVSS 4.6No exploitEPSS 0%

      pingtel · xpressaJul 23, 2002

    • CVE-2002-0673
      18Monitor

      The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the

      MediumCVSS 4.6No exploitEPSS 0%

      pingtel · xpressaJul 23, 2002