CVE Vulnerabilities

CVE-2013-6838

Published: Jan 28, 2014 | Modified: Jan 31, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

An unspecified Enghouse Interactive Professional Services addon product in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers installations, which allows remote attackers to gain privileges by leveraging knowledge of this key.

Affected Software

Name Vendor Start Version End Version
Ivr_pro Enghouseinteractive 9.0.3 (including) 9.0.3 (including)

References