CVE Vulnerabilities

CVE-2013-6838

Published: Jan 28, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An unspecified Enghouse Interactive Professional Services addon product in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers installations, which allows remote attackers to gain privileges by leveraging knowledge of this key.

Affected Software

NameVendorStart VersionEnd Version
Ivr_proEnghouseinteractive9.0.3 (including)9.0.3 (including)

References