US-CERT
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

 Other Documents
Technical Alerts

Technical Bulletins

Alerts

Security Tips

Nortel Networks, Inc. Information for VU#726548

Date Notified:2003-05-28
Date Updated:
Statement Date:
Status Summary:Vulnerable

Vendor Statement

Nortel Networks CallPilot and Meridian Mail voicemail systems do not generally authenticate by Caller ID but require a mailbox number + password to authenticate access to the mailbox. For additional security, users are forced to change the default password assigned to a newly created mailbox, the first time they logon. The only exception is where the auto logon feature is specifically configured by the administrator for a mailbox, in which case a user at the given Directory Number can access the corresponding mailbox without entering the mailbox number + password. Nortel Networks voicemail systems do not hard code or default to this behavior.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Produced 2009 by US-CERT, a government organization
Disclaimers and copyright information