CVE-2019-20028: Nec SL1100 Firmware

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.

Affected products

  • Nec SL1100 Firmware: any version
  • Nec SL2100 Firmware: any version
  • Nec SV8100 Firmware: any version
  • Nec SV9100 Firmware: any version

Published 2020-07-29. Last modified 2026-06-17.