9

CVE-2018-10093

Exploit
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Audiocodes420hd Ip Phone Firmware Version2.2.12.126
   Audiocodes420hd Ip Phone Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 68.68% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

http://packetstormsecurity.com/files/151116/AudioCode-400HD-Remote-Command-Injection.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2019/Jan/38
Third Party Advisory
Exploit
Mailing List
https://www.exploit-db.com/exploits/46164/
Third Party Advisory
Exploit
VDB Entry