CVE detail
CVE-2019-20027 — CVE-2019-20027
Published 2020-07-29 · Modified 2026-06-17 · Vendor nec · Product sv8100_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0137
EPSS probability
exploitation probability, 30d
69.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References