Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2023-22957
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.
0
Attacker Value
Unknown
CVE-2023-22956
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.
0
Attacker Value
Unknown
CVE-2023-22955
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.
0
Attacker Value
Unknown
CVE-2022-24632
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.
0
Attacker Value
Unknown
CVE-2022-24631
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.
0
Attacker Value
Unknown
CVE-2022-24630
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.
0
Attacker Value
Unknown
CVE-2022-24629
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.
0
Attacker Value
Unknown
CVE-2022-24628
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php.
0
Attacker Value
Unknown
CVE-2022-24627
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.
0
Attacker Value
Unknown
CVE-2019-9229
Disclosure Date: July 20, 2019 (last updated November 27, 2024)
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.
0