Show filters
174 Total Results
Displaying 21-30 of 174
Sort by:
Attacker Value
Unknown

CVE-2023-39559

Disclosure Date: August 29, 2023 (last updated October 08, 2023)
AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.
Attacker Value
Unknown

CVE-2023-39558

Disclosure Date: August 29, 2023 (last updated October 08, 2023)
AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai Data component.
Attacker Value
Unknown

CVE-2020-18781

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.
Attacker Value
Unknown

CVE-2023-22957

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.
Attacker Value
Unknown

CVE-2023-22956

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.
Attacker Value
Unknown

CVE-2023-22955

Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.
Attacker Value
Unknown

CVE-2022-24632

Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.
Attacker Value
Unknown

CVE-2022-24631

Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.
Attacker Value
Unknown

CVE-2022-24630

Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.
Attacker Value
Unknown

CVE-2022-24629

Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.