← Vulnerability feed

Vulnerability record · CVE-2008-3081 · published 9 July 2008

CVE-2008-3081: Avaya messaging storage server improper input validation vulnerability

Avaya · Messaging Storage Server

Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.

6.5 CVSS 2.0 Medium EPSS 3.1% · top 12.9% CWE-20 · Improper input validation
6.5CVSS 2.0 base score
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
42References
16 Jun 2026Last modified by NVD

Description

Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://osvdb.org/46587
http://secunia.com/advisories/30777 Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-269.htm
http://www.securityfocus.com/bid/29938
http://www.voipshield.com/research-details.php?id=100
http://www.voipshield.com/research-details.php?id=101
http://www.voipshield.com/research-details.php?id=102
http://www.voipshield.com/research-details.php?id=103
http://www.voipshield.com/research-details.php?id=104
http://www.voipshield.com/research-details.php?id=92
http://www.voipshield.com/research-details.php?id=93
http://www.voipshield.com/research-details.php?id=94
http://www.voipshield.com/research-details.php?id=95
http://www.voipshield.com/research-details.php?id=96
http://www.voipshield.com/research-details.php?id=97
http://www.voipshield.com/research-details.php?id=98
http://www.voipshield.com/research-details.php?id=99
http://www.vupen.com/english/advisories/2008/1945/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/43422
https://exchange.xforce.ibmcloud.com/vulnerabilities/43423
https://exchange.xforce.ibmcloud.com/vulnerabilities/43424
http://osvdb.org/46587
http://secunia.com/advisories/30777 Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2008-269.htm
http://www.securityfocus.com/bid/29938
http://www.voipshield.com/research-details.php?id=100
http://www.voipshield.com/research-details.php?id=101
http://www.voipshield.com/research-details.php?id=102
http://www.voipshield.com/research-details.php?id=103
http://www.voipshield.com/research-details.php?id=104
http://www.voipshield.com/research-details.php?id=92
http://www.voipshield.com/research-details.php?id=93
http://www.voipshield.com/research-details.php?id=94
http://www.voipshield.com/research-details.php?id=95
http://www.voipshield.com/research-details.php?id=96
http://www.voipshield.com/research-details.php?id=97
http://www.voipshield.com/research-details.php?id=98
http://www.voipshield.com/research-details.php?id=99
http://www.vupen.com/english/advisories/2008/1945/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/43422

Track CVE-2008-3081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2009-0115Christophe.varoqui multipath-tools incorrect permission assignment vulnerabilityThe Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server …EPSS 0.49%7.8CVE-2008-2812Linux kernel null pointer dereference vulnerabilityThe Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or p…EPSS 0.43%7.8CVE-2007-5830Avaya message networking improper input validation vulnerabilityUnspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, al…EPSS 1.6%5.5CVE-2006-1058Busybox vulnerabilityBusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file usi…EPSS 0.29%5.5CVE-2001-1494Kernel util-linux link following vulnerabilityscript command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log f…EPSS 0.43%9.5CVE-2026-88771Citrix netscaler application delivery controller improper input validation vulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEVEPSS 1.1%9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2008-3081), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.