CVE-2019-20028: Nec SL1100 Firmware
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.
Affected products
- Nec SL1100 Firmware: any version
- Nec SL2100 Firmware: any version
- Nec SV8100 Firmware: any version
- Nec SV9100 Firmware: any version
Published 2020-07-29. Last modified 2026-06-17.