| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40013 | Hig | 0.39 | 7.1 | 0.00 | Aug 14, 2023 | SVG Loader is a javascript library that fetches SVGs using XMLHttpRequests and injects the SVG code in the tag's place. According to the docs, svg-loader will strip all JS code before injecting the SVG file for security reasons but the input sanitization logic is not sufficient… | ||
| CVE-2023-39829 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function. | ||
| CVE-2023-39828 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function. | ||
| CVE-2023-39827 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function. | ||
| CVE-2023-21269 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2023 | In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21265 | Hig | 0.49 | 7.5 | 0.00 | Aug 14, 2023 | In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-39908 | Hig | 0.49 | 7.5 | 0.00 | Aug 14, 2023 | The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory. | ||
| CVE-2023-28483 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration… | ||
| CVE-2023-28481 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2023 | An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an attacker to obtain password-less SSH key… | ||
| CVE-2023-38741 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of… | ||
| CVE-2023-38721 | Hig | 0.55 | 8.4 | 0.00 | Aug 14, 2023 | The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system. IBM X-Force ID: 262173. | ||
| CVE-2023-0872 | Hig | 0.50 | 8.2 | 0.03 | Aug 14, 2023 | The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer.… | ||
| CVE-2023-33013 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2023 | A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request. | ||
| CVE-2023-31041 | Hig | 0.49 | 7.5 | 0.00 | Aug 14, 2023 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure. | ||
| CVE-2023-30754 | Hig | 0.46 | 7.1 | 0.00 | Aug 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin <= 1.8.5 versions. | ||
| CVE-2023-30489 | Hig | 0.46 | 7.1 | 0.00 | Aug 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions. | ||
| CVE-2023-28535 | Hig | 0.46 | 7.1 | 0.00 | Aug 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <= 2.2.0 versions. | ||
| CVE-2023-30483 | Hig | 0.46 | 7.1 | 0.00 | Aug 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9.2 versions. | ||
| CVE-2023-30475 | Hig | 0.46 | 7.1 | 0.00 | Aug 14, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin – Coupon Affiliates plugin <= 5.4.5 versions. | ||
| CVE-2023-30188 | Hig | 0.49 | 7.5 | 0.02 | Aug 14, 2023 | Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file. | ||
| CVE-2023-3160 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2023 | The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions. | ||
| CVE-2023-40303 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2023 | GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before… | ||
| CVE-2023-3263 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid… | ||
| CVE-2023-40296 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets. | ||
| CVE-2023-40295 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2023 | libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c. | ||
| CVE-2023-3261 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted… | ||
| CVE-2023-3260 | Hig | 0.47 | 7.2 | 0.01 | Aug 14, 2023 | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system. | ||
| CVE-2023-40283 | Hig | 0.00 | 7.8 | 0.01 | Aug 14, 2023 | An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled. | ||
| CVE-2023-40274 | Hig | 0.42 | 7.5 | 0.01 | Aug 14, 2023 | An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of… | ||
| CVE-2023-39406 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart. | ||
| CVE-2023-39404 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-39397 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-39395 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-39394 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified. | ||
| CVE-2023-39391 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-39390 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-39386 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart. | ||
| CVE-2023-39396 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-39393 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten. | ||
| CVE-2023-39392 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten. | ||
| CVE-2023-39389 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | ||
| CVE-2023-39388 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability. | ||
| CVE-2023-39384 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-39383 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security. | ||
| CVE-2023-39382 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart. | ||
| CVE-2023-39381 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-39380 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. | ||
| CVE-2023-4293 | Hig | 0.50 | 8.8 | 0.01 | Aug 12, 2023 | The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers,… | ||
| CVE-2023-22957 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2023 | An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the… | ||
| CVE-2023-22956 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2023 | An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information. |
- risk 0.39cvss 7.1epss 0.00
SVG Loader is a javascript library that fetches SVGs using XMLHttpRequests and injects the SVG code in the tag's place. According to the docs, svg-loader will strip all JS code before injecting the SVG file for security reasons but the input sanitization logic is not sufficient…
- risk 0.49cvss 7.5epss 0.01
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.
- risk 0.49cvss 7.5epss 0.01
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.
- risk 0.49cvss 7.5epss 0.01
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.
- risk 0.51cvss 7.8epss 0.00
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.49cvss 7.5epss 0.00
In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.49cvss 7.5epss 0.00
The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an attacker to obtain password-less SSH key…
- risk 0.49cvss 7.5epss 0.01
IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of…
- risk 0.55cvss 8.4epss 0.00
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system. IBM X-Force ID: 262173.
- risk 0.50cvss 8.2epss 0.03
The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer.…
- risk 0.57cvss 8.8epss 0.01
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin <= 1.8.5 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <= 2.2.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin – Coupon Affiliates plugin <= 5.4.5 versions.
- risk 0.49cvss 7.5epss 0.02
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
- risk 0.51cvss 7.8epss 0.00
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.
- risk 0.51cvss 7.8epss 0.00
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before…
- risk 0.49cvss 7.5epss 0.01
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid…
- risk 0.49cvss 7.5epss 0.01
async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.
- risk 0.57cvss 8.8epss 0.01
libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.
- risk 0.49cvss 7.5epss 0.01
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted…
- risk 0.47cvss 7.2epss 0.01
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.
- risk 0.00cvss 7.8epss 0.01
An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of…
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.
- risk 0.49cvss 7.5epss 0.00
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.
- risk 0.50cvss 8.8epss 0.01
The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers,…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.